ffHelper.exe

ffHelper Application

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application ffHelper.exe, “Helper Application for IE” by Visicom Media has been detected as a potentially unwanted program by 0 anti-malware scanners.
Publisher:
Visicom Media Inc.  (signed and verified)

Product:
ffHelper Application

Description:
Helper Application for IE

Version:
1, 0, 0, 10

MD5:
4f6a76405ede3323d509efcb0c8f330b

SHA-1:
a6f40ca59b71464e9133dfbc5da39492a263b846

SHA-256:
8f11cdf47b53eac252dd48696d8a49a4465f80082639919cf51c3f3c1d28c9d4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 7:49:48 PM UTC  (today)

File size:
99.1 KB (101,440 bytes)

Product version:
1, 0, 0, 10

Copyright:
Copyright (C) 2012

Original file name:
ffHelper.exe

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Common path:
C:\Program Files\manycam\ffhelper.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
4/17/2012 7:00:00 PM

Valid to:
6/21/2014 6:59:59 PM

Subject:
CN=Visicom Media Inc., OU=SECURE APPLICATION DEVELOPMENT, O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2B19B54BB7ABEE1A2623111C029AF449

File PE Metadata
Compilation timestamp:
6/21/2012 2:13:16 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:WCMvP+qP44XzL/Xp8hkw0OYzYwnhKgxy+D4a6e3TfBhmsisnWp6+:Wnvy6zLZnY5gxy+DH62fBhnWpl

Entry address:
0x2E51

Entry point:
E8, 85, 3A, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 28, 47, 41, 00, 89, 0D, 24, 47, 41, 00, 89, 15, 20, 47, 41, 00, 89, 1D, 1C, 47, 41, 00, 89, 35, 18, 47, 41, 00, 89, 3D, 14, 47, 41, 00, 66, 8C, 15, 40, 47, 41, 00, 66, 8C, 0D, 34, 47, 41, 00, 66, 8C, 1D, 10, 47, 41, 00, 66, 8C, 05, 0C, 47, 41, 00, 66, 8C, 25, 08, 47, 41, 00, 66, 8C, 2D, 04, 47, 41, 00, 9C, 8F, 05, 38, 47, 41, 00, 8B, 45, 00, A3, 2C, 47, 41, 00, 8B, 45, 04, A3, 30, 47, 41, 00, 8D, 45, 08, A3, 3C, 47, 41...
 
[+]

Entropy:
6.6760

Code size:
55 KB (56,320 bytes)

Remove ffHelper.exe - Powered by Reason Core Security