Should I block it?

No, this file is 100% safe to run.

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegDeleteKeyA, RegDeleteValueA, RegOpenKeyExA, RegQueryValueExA, RegCloseKey, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RegEnumKeyExA, RegSetValueExA, RegCreateKeyExA, RegEnumValueA, FreeSid, AllocateAndInitializeSid, GetAce, SetKernelObjectSecurity, GetSecurityDescriptorDacl, SetSecurityInfo, InitializeAcl, AddAccessAllowedAce, ControlService, CloseServiceHandle, OpenServiceA, OpenSCManagerA, StartServiceA, IsValidSid, GetLengthSid
kernel32.dll
GetCommandLineA, GetCurrentProcess, SetPriorityClass, GetTickCount, FormatMessageA, WideCharToMultiByte, MultiByteToWideChar, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, DeleteFileA, GetWindowsDirectoryA, GetCurrentThreadId, WriteFile, SetFilePointer, GetFileSize, CreateFileA, GetCurrentProcessId, GetLocalTime, WaitForSingleObject, SetEvent, ResetEvent, CreateEventA, OpenEventA, SetThreadPriority, GetModuleFileNameA, SetLastError, GetVersionExA, GetExitCodeProcess, CreateProcessA, ReleaseMutex, CreateMutexA, lstrcpynA, lstrcatA, lstrcpyA, InterlockedIncrement, InterlockedDecrement, TerminateThread, RaiseException, RtlUnwind, ExitProcess, GetStartupInfoA, ExitThread, TlsSetValue, TlsGetValue, CreateThread, HeapAlloc, HeapFree, GetCPInfo, HeapReAlloc, LCMapStringA, LCMapStringW, GetTimeFormatA, GetDateFormatA, CompareStringA, CompareStringW, GetStringTypeA, GetStringTypeW, SetUnhandledExceptionFilter, TlsFree, TlsAlloc, QueryPerformanceCounter, GetSystemTimeAsFileTime, TerminateProcess, HeapSize, GetStdHandle, UnhandledExceptionFilter, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, HeapDestroy, HeapCreate, VirtualFree, GetACP, GetOEMCP, FlushFileBuffers, VirtualProtect, VirtualAlloc, GetSystemInfo, VirtualQuery, IsBadWritePtr, GetUserDefaultLCID, EnumSystemLocalesA, IsValidLocale, IsValidCodePage, IsBadReadPtr, IsBadCodePtr, GetTimeZoneInformation, SetStdHandle, ReadFile, GetLocaleInfoW, SetEndOfFile, SetEnvironmentVariableA, CloseHandle, GetSystemDirectoryA, GetComputerNameA, Sleep, GetModuleHandleA, LoadLibraryA, GetProcAddress, GetLastError, GetLocaleInfoA, FreeLibrary
ole32.dll
CoReleaseServerProcess, CoAddRefServerProcess
user32.dll
FindWindowA, SendMessageA
winspool.drv
DeleteMonitorA

dlbtcoms.exe

Printer Communication System by Dell Inc. (Signed)

Remove dlbtcoms.exe
Version:   6.4.25.0
MD5:   d796f82bc518e9e0d3a7b8048f9ccc2b
SHA1:   6ef1ae909ae143eec7539303e56c5abea40ed1ea
SHA256:   3a722347a5f1f593b5dc47f89cc59a97ecf2ed5d957be9b24e90d25b882d77bc

Overview

dlbtcoms.exe runs as a service under the name dlbt_device within the local user context. It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. The file is digitally signed by Dell Inc. which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:dlbtcoms.exe
Product name:Printer Communication System
Typical file path:C:\Windows\System32\dlbtcoms.exe
Original name:GN__coms.exe
File version:6.4.25.0
Size:525.48 KB (538,096 bytes)
Certificate
Issued to:Dell Inc.
Authority (CA):VeriSign
Effective date:Thursday, December 14, 2006
Expiration date:Sunday, January 10, 2010
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'dlbt_device'
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\WINDOWS\system32\dlbtcoms.exe'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00063551%
0.028634%
Kernel CPU:0.00061930%
0.013761%
User CPU:0.00001621%
0.014873%
Kernel CPU time:635 ms/min
100,923,805ms/min
CPU cycles:150,989/sec
17,470,203/sec
Context switches:1/sec
284/sec
Memory
Private memory:3.67 MB
21.59 MB
Private (maximum):4.68 MB
Private (minimum):3.64 MB
Non-paged memory:3.67 MB
21.59 MB
Virtual memory:50.38 MB
140.96 MB
Virtual memory (peak):68.43 MB
169.69 MB
Working set:4.1 MB
18.61 MB
Working set (peak):7.52 MB
37.95 MB
Page faults:33,094/min
2,039/min
I/O
I/O read transfer:438 Bytes/sec
1.02 MB/min
I/O read operations:21/sec
343/min
I/O write transfer:1.98 KB/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:126 Bytes/sec
448.09 KB/min
I/O other operations:63/sec
1,671/min
Resource allocations
Threads:5
12
Handles:113
600
GUI GDI count:4
103
GUI USER count:1
49

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:C:\Windows\System32\dlbtcoms.exe -service
Owner:User
Windows Service
Service name:dlbt_device
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (by Microsoft)

ResourcesThreads

Averages
 
dlbtcoms.exe (main module)
Total CPU:0.00007993%
0.272967%
Kernel CPU:0.00005804%
0.107585%
User CPU:0.00002189%
0.165382%
CPU cycles:3,142/sec
5,741,424/sec
Memory:544 KB
1.16 MB
lxbxusb1.dll (Printer Communication System)
Total CPU:0.00002920%
Kernel CPU:0.00000000%
User CPU:0.00002920%
CPU cycles:237,992/sec
Context switches:1/sec
Memory:980 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 50.00%
Windows Vista Home Premium 50.00%

Distribution by countryDistribution by country

Germany installs about 50.00% of Printer Communication System.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 60.00%
ASUS 40.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE