aceftp3pro.exe

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application aceftp3pro.exe by Visicom Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Visicom Media Inc.  (signed and verified)

MD5:
9ac522f667c8a9c33bfa36ffd80ca4bf

SHA-1:
c826be8c7422762bbbc04016ac116714bf698f6c

SHA-256:
09b91ebd87e21e9ba74dded8eb1787df6a8e615ca681ee89c991a0eb3d828715

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/16/2024 8:57:22 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Visicom.VisicomMedia (M)
16.2.10.13

File size:
2.4 MB (2,484,304 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\прграммы замякина\soft\aceftp pro v3.70.3\aceftp3pro.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
5/12/2004 11:45:00 PM

Valid to:
6/20/2005 2:44:48 PM

Subject:
L=Brossard, S=Quebec, C=CA, OU=Secure Application Development, O=Visicom Media Inc., CN=Visicom Media Inc.

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
3E2E5E

File PE Metadata
Compilation timestamp:
10/23/2004 3:17:55 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:/kyTXTy6Zf67wbgOquEepqev9cwR3oT/I1c2nKlAAJLi9Gr/6XTlyhTI/wbPiH:cyXTZfBKOcwQ/MBnGAWe9TXhcTVbPiH

Entry address:
0x3C4B

Entry point:
83, EC, 20, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, C6, 44, 24, 14, 20, FF, 15, 28, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 68, 80, 92, 40, 00, 68, 40, 3B, 42, 00, A3, F0, 43, 42, 00, E8, 8F, 2A, 00, 00, BE, 00, B4, 42, 00, BF, 00, 04, 00, 00, 56, 57, FF, 15, C8, 70, 40, 00, E8, 7A, FF, FF, FF, 8B, 2D, 8C, 70, 40, 00, 85, C0, 75, 21, 68, FB, 03, 00, 00, 56, FF, 15, C4, 70, 40, 00, 68, 78, 92, 40, 00, 56, FF, D5, E8, 57, FF, FF, FF, 85, C0, 0F, 84, 47, 01, 00, 00, BE, 00, A0...
 
[+]

Code size:
23 KB (23,552 bytes)

Remove aceftp3pro.exe - Powered by Reason Core Security