1_offer_5.exe

Visual Tools

The application 1_offer_5.exe by Visual Tools has been detected as adware by 4 anti-malware scanners. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. It is also typically executed from the user's temporary directory.
Publisher:
Visual Tools  (signed and verified)

MD5:
0b0cb851143ce0ba7dd8fd29176e791f

SHA-1:
6751384672769e99d6c05de7c61b5f36af46b9d7

SHA-256:
6ee779abaa6fbbfe2432237b6b828b49272f4aa1745d2e7da30d3268db7a8173

Scanner detections:
4 / 68

Status:
Adware

Analysis date:
4/26/2024 9:35:19 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Babylon.25
9.0.1.05190

ESET NOD32
Win32/Toolbar.Babylon.H potentially unwanted application
7.0.302.0

Malwarebytes
PUP.Optional.ToolBarInstaller.A
v2014.07.30.12

Reason Heuristics
PUP.VisualTools.J
14.8.7.22

File size:
647.5 KB (663,024 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\1_offer_5.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
1/10/2013 3:00:00 AM

Valid to:
1/11/2015 2:59:59 AM

Subject:
CN=Visual Tools, O=Visual Tools, L=Belgrade, S=Serbia, C=RS

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
789958B0264F06055619270074AFA61F

File PE Metadata
Compilation timestamp:
10/31/2013 6:23:08 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:94RMZqBJcXqv8UZ17Zw45BeChlXT4BthWwH721YcVPZqGoaLKGGV00mv:94OZKJcXELZYLChZGWwH7cVPZqGoslSk

Entry address:
0x1C35

Entry point:
55, 8B, EC, 83, E4, F8, B8, 7C, 1A, 00, 00, E8, BB, 62, 00, 00, 53, 56, 33, DB, 57, 8D, 8C, 24, E0, 07, 00, 00, 88, 5C, 24, 0E, C6, 44, 24, 0F, 01, E8, E6, 1A, 00, 00, 53, 89, 9C, 24, 3C, 0A, 00, 00, 89, 9C, 24, 40, 0A, 00, 00, 89, 9C, 24, 44, 0A, 00, 00, C7, 84, 24, 48, 0A, 00, 00, 03, 00, 00, 00, FF, 94, 24, 20, 08, 00, 00, 8D, 8C, 24, E0, 07, 00, 00, 89, 84, 24, 34, 0A, 00, 00, E8, 6D, FA, FF, FF, 8D, 8C, 24, E0, 07, 00, 00, E8, DF, FA, FF, FF, 85, C0, 0F, 85, ED, 00, 00, 00, 8D, 44, 24, 10, 50, 8D, 8C...
 
[+]

Entropy:
7.8660

Developed / compiled with:
Microsoft Visual C++

Code size:
30 KB (30,720 bytes)

Remove 1_offer_5.exe - Powered by Reason Core Security