nasdaqtoolbar.exe

NASDAQ Quote Toolbar

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application nasdaqtoolbar.exe, “NASDAQ Quote Toolbar installer.” by Visicom Media has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.nasdaq.com.
Publisher:
Visicom Media Ltd.  (signed by Visicom Media Inc.)

Product:
NASDAQ Quote Toolbar

Description:
NASDAQ Quote Toolbar installer.

Version:
3.5.2

MD5:
ce1bb55e448e230a76bc63f18a766a18

SHA-1:
6063068dc0dcde03f34416a949f1e3b95bc4e26e

SHA-256:
1d11aaf6c1c6793ab4fe7b362036450b1e38d9e608df16bc4520ff0bd575881c

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 7:59:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.VisicomMedia.N
14.8.7.19

Rising Antivirus
JS:Malware.OddJS!5.3E
23.00.65.14124

File size:
1018.7 KB (1,043,136 bytes)

Product version:
3.5.2.0

Copyright:
Visicom Media Inc. (License)

Trademarks:
Visicom Media Inc, All Rights Reserved

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
5/27/2008 8:00:00 PM

Valid to:
6/22/2010 7:59:59 PM

Subject:
CN=Visicom Media Inc., OU=SECURE APPLICATION DEVELOPMENT, O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
70DEF7A1CF826EC0B9F2257933EA429B

File PE Metadata
Compilation timestamp:
2/8/2008 4:25:06 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:kJzURjSlfR1SyOFNxJ6F6KaIVCqK6M+3HflU615+DrbBfg4Rwca:qU5SkrXxJRnI6cUg4uca

Entry address:
0x3225

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 28, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, F9, 2A, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 50, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B0, 91, 40, 00, 68, A0, 36, 42, 00, E8, B0, 27, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 9E, 27, 00, 00...
 
[+]

Entropy:
7.9714

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file nasdaqtoolbar.exe has been seen being distributed by the following URL.

Remove nasdaqtoolbar.exe - Powered by Reason Core Security