pmxh.dll

PremierOpinion

Voicefive Networks, Inc.

The component is part of the TMRG platform which will track various behaviors of web browsing habits including tracking sites and domains visited as well as ads clicked. The module pmxh.dll by Voicefive Networks has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
Voicefive Networks, Inc.  (signed and verified)

Product:
PremierOpinion

Version:
1, 3, 331, 2

MD5:
c9b9fd307e740a20b058cccb92b1b0b5

SHA-1:
43faac557e4f1154302edd62213230b26c5d5082

SHA-256:
567276d0555d7de457741d641a2cc7ad15675306f98466767508362edd484398

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/6/2024 10:45:09 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.TMRG.VoicefiveNetworks (M)
15.12.9.21

File size:
157 KB (160,808 bytes)

Product version:
1, 3, 331, 2

Copyright:
Copyright (C) 2011

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\pmxh.dll

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/27/2011 8:00:00 PM

Valid to:
7/27/2013 7:59:59 PM

Subject:
CN="Voicefive Networks, Inc.", O="Voicefive Networks, Inc.", L=Reston, S=Virginia, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5CD88A0E7C5DFF13A6D5D79E1406B94B

File PE Metadata
Compilation timestamp:
9/29/2011 11:10:00 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
1536:XpFTDjloEUBo2NTmLcN5mH2S/8Pr2KrJSk6hGRgB0cUp/nfJrBy0g4gFZJJ8q1tv:jTDJUHTY8jJrDaMJ44gFZj8QtZnu2Qgl

Entry address:
0xCA64

Entry point:
83, 7C, 24, 08, 01, 75, 05, E8, D1, 4F, 00, 00, FF, 74, 24, 04, 8B, 4C, 24, 10, 8B, 54, 24, 0C, E8, ED, FE, FF, FF, 59, C2, 0C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9...
 
[+]

Entropy:
6.1766

Code size:
100 KB (102,400 bytes)

Remove pmxh.dll - Powered by Reason Core Security