MsgPlusDriver.sys

Messenger Plus! Virtual Camera

Kimahri Software inc.

This adware uses the Crossrider platform to build and distribute this web browser advertising injection extension. Once installed in the browser it will hijack various browser settings (homepage, search) and may interfere and track behaviors as well as deliver ads. The file MsgPlusDriver.sys, “MsgPlusDriver WDM Driver” by Kimahri Software inc has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a Windows 64-bit kernel mode device driver named “Messenger Plus! Virtual Camera”. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Yune Software  (signed by Kimahri Software inc.)

Product:
Messenger Plus! Virtual Camera

Description:
MsgPlusDriver WDM Driver

Version:
6, 0, 0, 780 built by: WinDDK

MD5:
9c2e5ec827066e3fc3e6211b211a4c7e

SHA-1:
a4fc98e7993aa4a7280a49b0ffa0994b8d44c247

SHA-256:
67c924f310dff1ffbfb1e4bd2491a4d2a72b4dea7ab5f5bc6fa755691955c160

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
7/7/2020 9:50:44 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.KimahriSoftwareinc.Q
14.3.1.10

File size:
122.5 KB (125,392 bytes)

Product version:
6, 0, 0, 780

Copyright:
(c) Yuna Software, All rights reserved.

Original file name:
MsgPlusDriver.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\msgplusdriver.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/20/2012 5:00:00 PM

Valid to:
6/21/2013 4:59:59 PM

Subject:
CN=Kimahri Software inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Kimahri Software inc., L=Montreal, S=Quebec, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
07C63B61BAA996BF90FF340CD94B17DA

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
1536:DyovQ6b7Z/uz0w71N2VdYDreBznDDnDDtDDI4DDDbDDD1Do5h15iMSxSDDDDDDDb:WoYa92owaVdYMR0RoqV

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, 5E, 43, FE, FF, CC, CC, 90, C1, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 48, C3, 01, 00, D0, 8D, 00, 00, 40, C1, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 6E, C4, 01, 00, 80, 8D, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 30, C4, 01, 00, 00, 00, 00, 00, 10, C4, 01, 00, 00, 00, 00, 00, F0, C3, 01, 00, 00, 00, 00, 00, D6, C3, 01, 00, 00, 00, 00, 00, BC, C3, 01, 00...
 
[+]

Driver
Display name:
Messenger Plus! Virtual Camera

Service name:
MsgPlusDriver

Type:
Kernel device driver (KernelDriver)


Remove MsgPlusDriver.sys - Powered by Reason Core Security