ftpexpert3.72.0.exe

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application ftpexpert3.72.0.exe by Visicom Media has been detected as a potentially unwanted program by 11 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from aurelie1617.free.fr.
Publisher:
Visicom Media Inc.  (signed and verified)

MD5:
a9a65a644d4da2789e36445d9e8e126c

SHA-1:
6807735e6c5351d4f555d774c3ae389e89e81136

SHA-256:
28461b9c0337d6c82e867589f8e25303a8ea0f438db0e95de70a7572ce9655f9

Scanner detections:
11 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 2:15:58 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
DR/BHO.ajt
7.11.120.124

Boost by Reason
Adware.VisicomMedia.N
2013.8.29.0

Comodo Security
Application.Win32.AdWare.BHO.VMNToolbar
17467

IKARUS anti.virus
Downloader.BHO.ajt
t3scan.2.2.29

Malwarebytes
Adware.BHO
v2013.08.29.12

NANO AntiVirus
Riskware.Win32.VMN.cdcnr
0.28.0.57029

Panda Antivirus
Adware/WebSearch
13.08.29.12

Quick Heal
AdWare.BHO.ajt.n8 (Not a Virus)
8.13.12.00

Reason Heuristics
PUP.VisicomMedia.N
14.8.7.19

Rising Antivirus
PE:Trojan.Win32.Generic.125E7501!308180225
23.00.65.13827

Vba32 AntiVirus
Signed-AdWare.Win32.MegaSearch.j
3.12.24.3

File size:
3.2 MB (3,337,416 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\ftpexpert3.72.0.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
6/23/2005 4:48:39 PM

Valid to:
6/20/2006 1:44:48 AM

Subject:
CN=Visicom Media Inc., OU=Secure Application Development, O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
3F88F4

File PE Metadata
Compilation timestamp:
4/7/2006 10:59:10 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:t2gKv6ebfeJeLna9afh6IQIvzmMntKH9Ct67:UgKyebfaeLJRQ8mMntKUt67

Entry address:
0x3137

Entry point:
81, EC, 7C, 01, 00, 00, 53, 55, 56, 33, F6, 57, 89, 74, 24, 18, BD, 40, 92, 40, 00, C6, 44, 24, 10, 20, FF, 15, 30, 70, 40, 00, 56, FF, 15, 70, 72, 40, 00, A3, F0, 43, 42, 00, 56, 8D, 44, 24, 30, 68, 60, 01, 00, 00, 50, 56, 68, 00, FD, 41, 00, FF, 15, 58, 71, 40, 00, 68, 30, 92, 40, 00, 68, 40, 3B, 42, 00, E8, 14, 28, 00, 00, BB, 00, B4, 42, 00, 53, 68, 00, 04, 00, 00, FF, 15, B4, 70, 40, 00, E8, 64, FF, FF, FF, 85, C0, 75, 24, 68, FB, 03, 00, 00, 53, FF, 15, B0, 70, 40, 00, 68, 28, 92, 40, 00, 53, E8, FF...
 
[+]

Entropy:
7.9978

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file ftpexpert3.72.0.exe has been seen being distributed by the following URL.

Remove ftpexpert3.72.0.exe - Powered by Reason Core Security