MsgPlusDriver.sys

Messenger Plus! Virtual Camera

Kimahri Software inc.

This adware uses the Crossrider platform to build and distribute this web browser advertising injection extension. Once installed in the browser it will hijack various browser settings (homepage, search) and may interfere and track behaviors as well as deliver ads. The file MsgPlusDriver.sys, “MsgPlusDriver WDM Driver” by Kimahri Software inc has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a Windows 64-bit kernel mode device driver named “Messenger Plus! Virtual Camera”. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Yune Software  (signed by Kimahri Software inc.)

Product:
Messenger Plus! Virtual Camera

Description:
MsgPlusDriver WDM Driver

Version:
6, 0, 0, 780 built by: WinDDK

MD5:
042dc664d0e47e13c6000f21cf510715

SHA-1:
036b34db332b5175218d89c55b8707398c885940

SHA-256:
bad61b43ca08d9a705e1fbc3ba8450a76aadf962ec98267765473b03f551399c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
10/1/2020 6:26:46 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.KimahriSoftwareinc.Q
14.2.16.10

File size:
115.3 KB (118,096 bytes)

Product version:
6, 0, 0, 780

Copyright:
(c) Yuna Software, All rights reserved.

Original file name:
MsgPlusDriver.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\msgplusdriver.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/21/2012 2:00:00 AM

Valid to:
6/22/2013 1:59:59 AM

Subject:
CN=Kimahri Software inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Kimahri Software inc., L=Montreal, S=Quebec, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
07C63B61BAA996BF90FF340CD94B17DA

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
1536:k5u16ldto7l8EO9JU2P7wzNDDnDDtDDI4DDDbDDD1Do5h15iMSxSDDDDDDDLDDD7:+u16lDUTQirRwRVD

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 42, 65, FE, FF, CC, CC, D8, 9F, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, A8, A1, 01, 00, B8, 74, 00, 00, A0, 9F, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, B6, A1, 01, 00, 80, 74, 00, 00, B0, 9F, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, D6, A2, 01, 00, 90, 74, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, F6, A0, 01, 00, 0A, A1, 01, 00, 8A, A0, 01, 00, 00, 00, 00, 00, 3E, A2, 01, 00, 78, A2, 01, 00, FC, A1, 01, 00, DC, A1...
 
[+]

Entropy:
5.5472

Driver
Display name:
Messenger Plus! Virtual Camera

Service name:
MsgPlusDriver

Type:
Kernel device driver (KernelDriver)


Remove MsgPlusDriver.sys - Powered by Reason Core Security