ftpexpert3.exe

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application ftpexpert3.exe by Visicom Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Visicom Media Inc.  (signed and verified)

MD5:
4a45985e615e48167a57a5fc30375bf7

SHA-1:
c1523a673ef175d31a043b248328be5ddf9d9be5

SHA-256:
ad724521772564c1acd06c6ac1bbfcfc0aaff0349cf5ab5f045960511088a80d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/24/2024 5:27:00 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Visicom.VisicomMedia (M)
16.3.7.16

File size:
2.4 MB (2,525,096 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\Music\music\nouveaute\house\ftpexpert3.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
5/12/2004 7:45:00 PM

Valid to:
6/20/2005 10:44:48 AM

Subject:
L=Brossard, S=Quebec, C=CA, OU=Secure Application Development, O=Visicom Media Inc., CN=Visicom Media Inc.

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
3E2E5E

File PE Metadata
Compilation timestamp:
10/23/2004 11:17:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:4ikPqnWnlBGP41X4Yj60gNBrwQh7C42hBTDz8ofFrEAnZjVKF3aEW:zJnB4q860seoC4wBTDzHZjg4

Entry address:
0x3C4B

Entry point:
83, EC, 20, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, C6, 44, 24, 14, 20, FF, 15, 28, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 68, 80, 92, 40, 00, 68, 40, 3B, 42, 00, A3, F0, 43, 42, 00, E8, 8F, 2A, 00, 00, BE, 00, B4, 42, 00, BF, 00, 04, 00, 00, 56, 57, FF, 15, C8, 70, 40, 00, E8, 7A, FF, FF, FF, 8B, 2D, 8C, 70, 40, 00, 85, C0, 75, 21, 68, FB, 03, 00, 00, 56, FF, 15, C4, 70, 40, 00, 68, 78, 92, 40, 00, 56, FF, D5, E8, 57, FF, FF, FF, 85, C0, 0F, 84, 47, 01, 00, 00, BE, 00, A0...
 
[+]

Code size:
23 KB (23,552 bytes)

Remove ftpexpert3.exe - Powered by Reason Core Security