multisearchbarcb.exe

multisearchbar changer

Venisoft Corp.

The application multisearchbarcb.exe by Venisoft has been detected as adware by 4 anti-malware scanners.
Publisher:
firsti  (signed by Venisoft Corp.)

Product:
multisearchbar changer

Description:
multisearchbar

Version:
1.0.0.0

MD5:
ef9783ca8b00c9eb01b44331a8a2766f

SHA-1:
36fa51d478adfee8d621e5329320ba5f512b91fc

Scanner detections:
4 / 68

Status:
Adware

Analysis date:
4/25/2024 10:01:08 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-PUP/Helper.MultiSearchBar.329360
2013.12.10

Malwarebytes
Adware.Addendum
v2014.04.28.10

Reason Heuristics
PUP.VenisoftCorp.Q
14.5.10.12

Trend Micro House Call
TROJ_GEN.F47V1209
7.2.118

File size:
321.6 KB (329,360 bytes)

Product version:
1.0.0.0

Original file name:
multisearchbarcb.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\addendum\sidebar\multisearchbar\multisearchbarcb.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
11/3/2010 9:00:00 AM

Valid to:
1/3/2012 8:59:59 AM

Subject:
CN=Venisoft Corp., OU=Development Team, O=Venisoft Corp., L=Guro-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
112122F77CF9C86B1DAEE0B516717C87

File PE Metadata
Compilation timestamp:
6/20/1992 7:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:03D7jy2VUZcKCH8CsMNk4jHyq9cO5Ad17UEZWucsmClu:03D7GHoE4v15An7ZVru

Entry address:
0x415B4

Entry point:
55, 8B, EC, 83, C4, F4, 53, B8, EC, 13, 44, 00, E8, 8F, 4A, FC, FF, 68, 24, 16, 44, 00, 6A, FF, 6A, 00, E8, 4D, 4B, FC, FF, 8B, D8, 85, DB, 74, 43, E8, D2, 4B, FC, FF, 85, C0, 75, 3A, A1, 00, 2D, 44, 00, 8B, 00, E8, 46, B9, FF, FF, 8B, 0D, 0C, 2B, 44, 00, A1, 00, 2D, 44, 00, 8B, 00, 8B, 15, 38, 08, 44, 00, E8, 46, B9, FF, FF, A1, 00, 2D, 44, 00, 8B, 00, E8, BA, B9, FF, FF, 85, DB, 74, 06, 53, E8, E4, 4A, FC, FF, 5B, E8, 9A, 22, FC, FF, 00, 00, 6D, 75, 6C, 74, 69, 73, 65, 61, 72, 63, 68, 62, 61, 72, 20, 43...
 
[+]

Entropy:
6.5821

Developed / compiled with:
Microsoft Visual C++

Code size:
258 KB (264,192 bytes)

Remove multisearchbarcb.exe - Powered by Reason Core Security