parentalcontrolsetup.exe

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application parentalcontrolsetup.exe by Visicom Media has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer.
Publisher:
Visicom Media Inc.  (signed and verified)

MD5:
b9f95b70697efc73f1c408377591f825

SHA-1:
8b157054a93c603c911f895b3aae6879f423a0cc

SHA-256:
07e48e7e098c790b90dcbae70cbf7a9eb5e29210a33c784410ae2752a5762946

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 10:49:31 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.Visicom
15.3.16.13

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

File size:
1.2 MB (1,210,816 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\parentalcontrolsetup.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
5/31/2006 2:00:00 AM

Valid to:
6/22/2007 1:59:59 AM

Subject:
CN=Visicom Media Inc., OU=SECURE APPLICATION DEVELOPMENT, O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
46009F112341EB9E47AD9A71D868DC95

File PE Metadata
Compilation timestamp:
12/17/2005 4:37:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:mRqhGai2l37GFoXrL8nV5+t3J1yiFINTyUt4ZT0i93KsuY8mOXh29NUp+:mohGbSGFo7LW2tZMB5t4uiFKd29NUM

Entry address:
0x32D3

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, F6, 57, 89, 74, 24, 18, BD, 68, 91, 40, 00, 89, 74, 24, 10, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 56, FF, 15, 84, 72, 40, 00, A3, 10, 44, 42, 00, 56, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 56, 68, 20, FD, 41, 00, FF, 15, 6C, 71, 40, 00, 68, 8C, 92, 40, 00, 68, 60, 3B, 42, 00, E8, D7, 27, 00, 00, BB, 00, B4, 42, 00, BF, 00, 04, 00, 00, 53, 57, FF, 15, B8, 70, 40, 00, E8, 5F, FF, FF, FF, 85, C0, 75, 24, 68, FB, 03, 00, 00, 53, FF, 15, B4, 70, 40, 00, 68, 84, 92...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

Remove parentalcontrolsetup.exe - Powered by Reason Core Security