mcvidrv.sys

ManyCam Virtual Webcam

ManyCam (VISICOM MÉDIA INC.)

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The file mcvidrv.sys, “ManyCam Virtual Webcam Driver” by ManyCam (VISICOM MÉDIA INC.) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a Windows 64-bit kernel mode device driver named “ManyCam Virtual Webcam”.
Publisher:
Visicom Media Inc.  (signed by ManyCam (VISICOM MÉDIA INC.))

Product:
ManyCam Virtual Webcam

Description:
ManyCam Virtual Webcam Driver

Version:
5.0.3.0

MD5:
fd5794501fd0ef08dd4bd0dc56c0d7dd

SHA-1:
1c65d8b933ef8e6e6adad03714bf113d87ff89af

SHA-256:
ba5a4303d9cb6b1d90e029fa16c89e26711a32d6422dbfa0180a97516b4a4d1d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/18/2024 6:24:54 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Visicom
17.3.13.15

File size:
48.9 KB (50,088 bytes)

Product version:
5.0.3.0

Copyright:
(c) 2006-2016 Visicom Media Inc.

Original file name:
mcvidrv.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\mcvidrv.sys

Digital Signature
Authority:
Symantec Corporation

Valid from:
3/1/2016 1:00:00 AM

Valid to:
3/2/2019 12:59:59 AM

Subject:
CN=ManyCam (VISICOM MÉDIA INC.), O=ManyCam (VISICOM MÉDIA INC.), L=Brossard, S=Quebec, C=CA, SERIALNUMBER=1145963121, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Quebec, OID.1.3.6.1.4.1.311.60.2.1.3=CA

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA - G2, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
041C319EDA4F5240F1802BA471E11BB9

File PE Metadata
Compilation timestamp:
2/8/2017 10:58:15 AM

OS version:
6.3

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
12.0

Entry address:
0xD000

Entry point:
48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8B, DA, 48, 8B, F9, E8, 17, 00, 00, 00, 48, 8B, D3, 48, 8B, CF, 48, 8B, 5C, 24, 30, 48, 83, C4, 20, 5F, E9, C6, 5A, FF, FF, CC, CC, 48, 8B, 05, 6D, DB, FF, FF, 45, 33, C9, 49, B8, 32, A2, DF, 2D, 99, 2B, 00, 00, 48, 85, C0, 74, 05, 49, 3B, C0, 75, 38, 0F, 31, 48, C1, E2, 20, 48, 8D, 0D, 49, DB, FF, FF, 48, 0B, C2, 48, 33, C1, 48, 89, 05, 3C, DB, FF, FF, 66, 44, 89, 0D, 3A, DB, FF, FF, 48, 8B, 05, 2D, DB, FF, FF, 48, 85, C0, 75, 0A, 49, 8B, C0, 48, 89, 05, 1E, DB...
 
[+]

Code size:
22 KB (22,528 bytes)

Driver
Display name:
ManyCam Virtual Webcam

Service name:
ManyCam

Type:
Kernel device driver (KernelDriver)


Remove mcvidrv.sys - Powered by Reason Core Security