panda_url_filteringd.sys

Anti-phishing Domain Advisor

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The file panda_url_filteringd.sys, “Visicom Media Anti-phishing Domain Advisor (Powered by Panda Security)” by Visicom Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a Windows kernel mode device driver named “panda_url_filteringd driver”.
Publisher:
Visicom Media Inc.  (signed and verified)

Product:
Anti-phishing Domain Advisor

Description:
Visicom Media Anti-phishing Domain Advisor (Powered by Panda Security)

Version:
2, 0, 0, 0

MD5:
763ab774bf0ee1156d8141de399ac415

SHA-1:
0b62a65b21596bb1b57b791cb4ff855497b9108a

SHA-256:
fecf3b2090ffc63ab8ad62041adc3a2d3f65156427f34447e176c753dadc88a0

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 3:09:53 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Visicom (M)
16.11.9.4

File size:
39.1 KB (40,024 bytes)

Product version:
2.0

Copyright:
Copyright (C) 2013 Visicom Media Inc.

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Program Files\panda security url filtering\panda_url_filteringd.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/8/2013 3:44:29 PM

Valid to:
11/9/2014 3:44:29 PM

Subject:
E=sysadmin@vmn.net, CN=Visicom Media Inc., O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11211539982821E53DCB554103CE4CFB4C45

File PE Metadata
Compilation timestamp:
12/20/2013 12:05:14 AM

OS version:
6.2

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
11.0

CTPH (ssdeep):
768:C7YHA6Xm9BD5t+f96UpcwxwMMW4sKsQ2pG8UOgQPrIO:8mATlt+F3OAGsj3NPN

Entry address:
0x906A

Entry point:
8B, FF, 55, 8B, EC, E8, 92, FF, FF, FF, 5D, E9, 8C, 7F, FF, FF, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 83, EC, 14, 53, 8D, 45, EC, 56, 89, 45, FC, B8, 00, 00, 00, 00, 8B, 75, FC, 33, DB, 33, C9, 33, D2, 0F, A2, 89, 06, 89, 5E, 04, 89, 4E, 08, 89, 56, 0C, 83, 7D, EC, 00, 75, 04, 32, C0, EB, 44, 81, 7D, F4, 6E, 74, 65, 6C, 74, 12, 81, 7D, F4, 63, 41, 4D, 44, 74, 09, 81, 7D, F4, 61, 75, 6C, 73, 75, E1, 8D, 45, EC, 89, 45, FC, B8, 01, 00, 00, 00, 8B, 75, FC, 33, DB, 33, C9, 33, D2, 0F, A2, 89, 06, 89, 5E...
 
[+]

Code size:
26 KB (26,624 bytes)

Driver
Display name:
panda_url_filteringd driver

Service name:
panda_url_filteringd

Type:
Kernel device driver (KernelDriver)


Remove panda_url_filteringd.sys - Powered by Reason Core Security