PE structurePE file structure

Import table
RegCreateKeyExW, RegSetValueExW, RegQueryValueExW, RegQueryValueExA, RegEnumKeyExA, RegQueryInfoKeyA, RegSetValueExA, RegOpenKeyExA, RegCreateKeyExA, RegCloseKey, RegDeleteValueA, RegDeleteKeyA, RegOpenKeyExW
GetDIBits, GetBitmapBits, CreateDIBSection, CreateDCA, CreateRectRgn, CreateRoundRectRgn, OffsetWindowOrgEx, SetWindowOrgEx, GetPixel, CreateSolidBrush, GetStockObject, GetObjectA, GetDeviceCaps, BitBlt, CreateCompatibleDC, CreateCompatibleBitmap, DeleteDC, CreateDIBitmap, DeleteObject, SelectObject
SizeofResource, LoadResource, FindResourceA, LoadLibraryExA, GetModuleHandleA, LockResource, FindResourceExA, FlushInstructionCache, GetCurrentProcess, HeapAlloc, ActivateActCtx, CreateActCtxA, ReleaseActCtx, DeactivateActCtx, TerminateThread, WaitForSingleObject, GetTickCount, OpenMutexA, CloseHandle, ReleaseMutex, GetCurrentThreadId, CreateThread, MulDiv, GlobalUnlock, GlobalLock, lstrcmpA, CreateMutexA, MapViewOfFile, CreateFileMappingA, OpenFileMappingA, Sleep, WritePrivateProfileStringA, GetPrivateProfileStringA, UnmapViewOfFile, GetProcAddress, LoadLibraryA, QueryPerformanceCounter, QueryPerformanceFrequency, IsBadCodePtr, TlsGetValue, SetEnvironmentVariableA, GetCurrentProcessId, SetFilePointer, SystemTimeToFileTime, GetFileAttributesA, CreateFileA, ReadFile, LocalFileTimeToFileTime, CreateDirectoryA, GetCurrentDirectoryA, FreeLibrary, WriteFile, SetLastError, LocalFree, GetLocaleInfoW, SetStdHandle, IsBadReadPtr, IsValidCodePage, IsValidLocale, EnumSystemLocalesA, GetUserDefaultLCID, GetStringTypeW, GetStringTypeA, UnhandledExceptionFilter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetStartupInfoA, GetFileType, GetStdHandle, SetHandleCount, GetOEMCP, FlushFileBuffers, TlsSetValue, TlsFree, TlsAlloc, SetUnhandledExceptionFilter, TerminateProcess, IsBadWritePtr, VirtualFree, HeapCreate, GetCPInfo, LCMapStringW, LCMapStringA, ExitProcess, GetCommandLineA, GetSystemTimeAsFileTime, RtlUnwind, VirtualQuery, GetSystemInfo, VirtualAlloc, VirtualProtect, HeapSize, HeapReAlloc, HeapDestroy, IsDBCSLeadByte, lstrcatA, GetModuleFileNameA, lstrcpyA, lstrcpynA, InterlockedDecrement, InterlockedIncrement, GetProcessHeap, HeapFree, LeaveCriticalSection, EnterCriticalSection, GlobalAlloc, GlobalFree, GetEnvironmentVariableA, lstrlenA, lstrlenW, lstrcmpiA, GetVersion, DeleteCriticalSection, InitializeCriticalSection, GetLastError, RaiseException, WideCharToMultiByte, MultiByteToWideChar, GetVersionExA, GetThreadLocale, GetLocaleInfoA, GetACP, SetFileTime, InterlockedExchange, SetEndOfFile
OleRun, CoTaskMemFree, CoGetObject, OleUninitialize, OleInitialize, CoGetClassObject, CreateStreamOnHGlobal, OleLockRunning, CLSIDFromString, CLSIDFromProgID, CoTaskMemAlloc, OleSaveToStream, WriteClassStm, OleLoadFromStream, CoInitialize, CoUninitialize, StringFromGUID2, CoCreateInstance, CoTaskMemRealloc
SHGetMalloc, SHGetSpecialFolderLocation, SHGetPathFromIDListA, ShellExecuteA, ShellExecuteExW
PathRemoveFileSpecA, PathCanonicalizeA, PathAddBackslashA, UrlEscapeW, SHDeleteKeyA, PathFindExtensionA, SHCreateStreamOnFileA
CoInternetGetSession, URLDownloadToFileA, IsValidURL
CreateAcceleratorTableA, UnhookWindowsHookEx, GetPropA, GetClassNameA, SetWindowPos, DestroyWindow, RedrawWindow, GetDlgItem, IsWindow, DestroyAcceleratorTable, IsChild, SetFocus, BeginPaint, GetWindowTextLengthA, RegisterWindowMessageA, OffsetRect, CallWindowProcW, SetTimer, SetPropA, SetWindowsHookExA, UnregisterClassA, PostMessageA, SetWindowLongA, GetWindowLongA, GetClientRect, CharNextA, DefWindowProcA, GetWindow, GetFocus, CallWindowProcA, EndDialog, DispatchMessageW, TranslateMessage, GetParent, MoveWindow, GetWindowRect, GetClassInfoExA, wsprintfA, FindWindowExA, ShowWindow, RegisterClassA, LoadIconA, KillTimer, MessageBoxA, GetKeyState, LoadStringA, GetSystemMetrics, CreateIcon, GetClassInfoA, UpdateWindow, PostQuitMessage, SetForegroundWindow, IsWindowVisible, SetParent, SetMenu, GetSystemMenu, SendMessageW, SetCursorPos, SetActiveWindow, GetMessageA, SetWindowRgn, GetWindowInfo, SetWindowLongW, GetWindowLongW, IsIconic, IsDlgButtonChecked, SetWindowTextW, CheckDlgButton, SystemParametersInfoA, GetActiveWindow, SetWindowTextA, DispatchMessageA, GetWindowTextA, LoadCursorA, SendMessageA, GetSysColor, CallNextHookEx, GetCursorPos, PtInRect, EqualRect, IntersectRect, SetRect, MapWindowPoints, CharLowerBuffA, CharUpperBuffA, RegisterClassExA, CreateWindowExA, WindowFromPoint, DialogBoxParamA, ReleaseCapture, SetCapture, FillRect, GetDC, ReleaseDC, InvalidateRect, InvalidateRgn, GetDesktopWindow, EndPaint, DeleteMenu
HttpSendRequestW, HttpOpenRequestW, FtpOpenFileW, HttpQueryInfoW, HttpQueryInfoA, InternetCloseHandle, FindFirstUrlCacheEntryA, DeleteUrlCacheEntry, FindNextUrlCacheEntryA, InternetGetConnectedState, InternetOpenW, InternetCrackUrlW, InternetConnectW, InternetReadFile
DTX Toolbar by Bandoo Media (Signed)

Version:   5, 0, 8, 210
MD5:   39ecb144372b2ed7b1b91a1e63d3f275
SHA1:   5618448e0195ba9251a1a0a5132ce2612037d630
SHA256:   6fa23696b59c5d4bd5c900ff18b7aeea788d3fc70c5e16aa622eac31043707e8

What is searchquband.dll?

This is a Visicom toolbar installed in your Web browser that collects and stores information about web browsing habits including pages visited and search queries performed and sends this information to Visicom so they can suggest services or provide various forms of advertisements via the toolbar.

About searchquband.dll (from Bandoo Media)

Visicom Media Toolbars use the DTX toolbar technology platform, an Ajax framework to develop toolbars and other extensions for Web browsers.


searchquband.dll is loaded as dynamic link library that runs in the context of a process. It is installed with a couple of know programs including Windows iLivid Toolbar published by Bandoo Media Inc, Windows Searchqu Toolbar from Bandoo Media Inc and Windows Searchqu Toolbar by Bandoo Media Inc. The file is digitally signed by Bandoo Media.


File name:searchquband.dll
Publisher:Visicom Media Inc
Product name:DTX Toolbar
Description:DTX kernel Module
Typical file path:C:\Program Files\Windows Searchqu Toolbar\Datamngr\ToolBar\searchquband.dll
Original name:dtBand.dll
File version:5, 0, 8, 210
Size:438.89 KB (449,424 bytes)
Issued to:Bandoo Media
Digital DNA
PE subsystem:Windows GUI
File packed:No
Bandoo Media Inc
  79% remove
Bandoo Media Inc
  88% remove
Bandoo Media Inc
  83% remove
Bandoo Media Inc
  88% remove
This toolbar is typiclaly bundled with the installation of the free iLivid software. Windows iLivid Toolbar by Bandoo for Intenet Explorer collects and stores information about your web browsing habits in order to suggest services or provide advertising via the toolbar. Windows iLivid Toolbar will change your home page and search provider during installation. The Toolbar is typically bundled with the free iLivid software as an option du...

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate N 100.00%

Distribution by countryDistribution by country

United States installs about 100.00% of DTX Toolbar.
