acehtml6pro.exe

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application acehtml6pro.exe by Visicom Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Visicom Media Inc.  (signed and verified)

MD5:
a50deeb469ba7bffd72edb884d8aed51

SHA-1:
e81d6832108eacfd5e9c2c52c2b79dba9b55746f

SHA-256:
6b727602bb85611e0b9f82ce978284be3a92154ba953ee7ec653bd8f337caaae

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/23/2024 7:51:33 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Visicom.VisicomMedia (M)
15.11.5.16

File size:
5.3 MB (5,593,912 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\acehtml6pro.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
5/12/2004 11:45:00 AM

Valid to:
6/20/2005 2:44:48 AM

Subject:
L=Brossard, S=Quebec, C=CA, OU=Secure Application Development, O=Visicom Media Inc., CN=Visicom Media Inc.

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
3E2E5E

File PE Metadata
Compilation timestamp:
10/23/2004 3:17:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:hsevStUJ9k/mHXcthiRnfFAL8q9C9SanszIuNLVSZqelWYPCjr8HLbi5t:xgUJS/mH1NAL8q9C4w+ISLVSZcYPA8HY

Entry address:
0x3C4B

Entry point:
83, EC, 20, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, C6, 44, 24, 14, 20, FF, 15, 28, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 68, 80, 92, 40, 00, 68, 40, 3B, 42, 00, A3, F0, 43, 42, 00, E8, 8F, 2A, 00, 00, BE, 00, B4, 42, 00, BF, 00, 04, 00, 00, 56, 57, FF, 15, C8, 70, 40, 00, E8, 7A, FF, FF, FF, 8B, 2D, 8C, 70, 40, 00, 85, C0, 75, 21, 68, FB, 03, 00, 00, 56, FF, 15, C4, 70, 40, 00, 68, 78, 92, 40, 00, 56, FF, D5, E8, 57, FF, FF, FF, 85, C0, 0F, 84, 47, 01, 00, 00, BE, 00, A0...
 
[+]

Entropy:
7.9994  (probably packed)

Code size:
23 KB (23,552 bytes)

Remove acehtml6pro.exe - Powered by Reason Core Security