Visicom Media Inc.

Publisher Information

Visicom Media Inc. is a software publisher located in Brossard, Quebec in Canada*. The company is a primary distributor of potentially unwanted software. Visicom is a Candian adware platform that distributes private labled toolbars for the purpose of injecting advertising within the web browser as well as providing search redirection. Visicom produces an anti-phising plugin for the browser in association with Panda Security for its various toolbar offerings in addition to operating the mystart.com search portal and toolbar. Thre are 9 additional code signing certificates issued to this publisher.
Remove Visicom Media Inc. Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
4/18/2012 7:00:00 AM

Valid to:
6/22/2014 6:59:59 AM

Subject:
CN=Visicom Media Inc., OU=SECURE APPLICATION DEVELOPMENT, O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2b19b54bb7abee1a2623111c029af449

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Visicom.VisicomMedia (M), PUP.Visicom.VisicomMedia.Installer (M), PUP.Visicom.VisicomMedia.Toolbar (M), PUP.APN.Visicom (M)
100.00%

ESET NOD32
Win32/Toolbar.Visicom.A potentially unwanted application, Win32/Toolbar.Visicom.B potentially unwanted application, Detection.Undefined
16.00%

ESET NOD32
Win32/Toolbar.Visicom (variant)
14.00%

Bkav FE
HW32.Laneul, W32.HfsAdware, W64.HfsAdware
14.00%

McAfee
Artemis!8370F1E1F0D3, Artemis!B659800523FE, Artemis!00B6A8C35C6A
12.00%

Trend Micro House Call
TROJ_GEN.F47V0521, TROJ_GEN.F47V0324, TROJ_GE.DAB0F271
12.00%

Emsisoft Anti-Malware
Gen:Variant.Zusy.81792, Gen:Variant.Symmi.10233, Android.Adware.Adwo, Trojan.JS.Iframe.BKL
12.00%

K7 Gateway Antivirus
Trojan
10.00%

K7 AntiVirus
Trojan
10.00%

Avira AntiVirus
TR/Trash.Gen
10.00%

10 / 68    (PUP)

10 / 68    (PUP)

1 / 68      (PUP)
dtuser.exe (by Visicom Media)  (4bbc8492e0a61db37d441466e3053457)

3 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)
urbar.exe (urbar by Visicom Media)  (d29300adf60d1f610d0502e8195a935b)

1 / 68      (PUP)
mapsx.dll (dtx Dynamic Link Library)  (f6ff56eaf6aca84a56484cc75358ce86)

1 / 68      (PUP)
maps.dll (DTX Toolbar by Visicom Media Inc)  (338c31adc0b32f0659c2d353ac07096d)

7 / 68      (PUP)
z_downloader.exe (ZGame Toolbar by Visicom Media)  (7b3205a43ff0ce6b3d0fb339df5bfc0b)

1 / 68      (PUP)

7 / 68      (PUP)
z_downloader.exe (ZGame Toolbar by Visicom Media)  (b18366eedf57ab993bb7659ebc521ea7)

7 / 68      (PUP)
z_downloader.exe (ZGame Toolbar by Visicom Media)  (f1a8f22e1269ee49c86ed6e9dc9aa0ef)

1 / 68      (PUP)
z_downloader.exe (ZGame Toolbar by Visicom Media)  (3aa8b45122cfb2fd8004ef734a88215e)

1 / 68      (PUP)
iliveto.exe (Ilive.to by Iguide)  (57e76b1815884ed7d4b6e35ab4840774)

1 / 68      (PUP)
dtuser.exe (by Visicom Media)  (5e5c1daf517e3682d9bcd6e895a74556)

1 / 68      (PUP)
yolobartb.dll (Yolobar by Visicom Media Inc)  (9272a6e26cd3381d3e156442bd839db5)

1 / 68      (PUP)

1 / 68      (PUP)
dealbrowsingyaDx.dll (DealBrowsing Toolbar)  (c07f6556f46313a9e04ed040b6e96a16)

1 / 68      (PUP)
iliveto.exe.dap (Ilive.to by Iguide)  (c62b94aa9e764f373ded3a3a315dd52e)

5 / 68      (PUP)
mystarttb64.dll (MyStart Toolbar by Visicom Media Inc)  (324348cfb10dd77fc381c093da641e8c)

11 / 68    (PUP)
mystarttb.dll (MyStart Toolbar by Visicom Media Inc)  (427fe5f7a1dd492c45aefdddb8a37375)

6 / 68      (PUP)
mystartDx64.dll (MyStart Toolbar)  (3119c9bbcd73896a0e822f45da8a71cb)

2 / 68      (PUP)
ffHelper.exe (ffHelper Application by Visicom Media)  (4f6a76405ede3323d509efcb0c8f330b)

1 / 68      (PUP)
dtuser.exe (by Visicom Media)  (ae20ff76f44c305130836dc3daeb1876)

10 / 68    (PUP)

10 / 68    (PUP)

3 / 68      (PUP)
blekkotb_019.dll (DTX Toolbar by Visicom Media Inc)  (845f642bd229ea9da207a2014d8ae3fe)

4 / 68      (PUP)
blekkotb_019x.dll (dtx Dynamic Link Library)  (4f39569f553c17715ddae90488d5583a)

 
Latest 30 of 812 files

Downloads URLs for files signed by Visicom Media Inc..

1 / 68      (PUP)
http://www.urplayzone.com/.../z_downloader.exe  (3aa8b45122cfb2fd8004ef734a88215e)

7 / 68      (PUP)
http://www.urplayzone.com/.../z_downloader.exe  (f1a8f22e1269ee49c86ed6e9dc9aa0ef)

7 / 68      (PUP)
http://www.urplayzone.com/.../z_downloader.exe  (b18366eedf57ab993bb7659ebc521ea7)

Top-level domains owned by Visicom Media Inc..

The certificates below are also signed by Visicom Media Inc..

0F7022688814C950B353E71B8D1C1D84  (Feb 08, 2015 to Feb 08, 2017)

266F9E30991B0C3EFC03DA9B8CDDB68D  (May 07, 2014 to Jun 20, 2016)

11211539982821E53DCB554103CE4CFB4C45  (Nov 08, 2013 to Nov 09, 2014)

73C74D9445094BFD79759F7B9CAFD730  (Jun 23, 2010 to Jun 21, 2012)

70DEF7A1CF826EC0B9F2257933EA429B  (May 27, 2008 to Jun 22, 2010)

53647B50983ED1EB11C279CB398C2CA4  (Jun 20, 2007 to Jun 22, 2008)

46009F112341EB9E47AD9A71D868DC95  (May 31, 2006 to Jun 22, 2007)

3F88F4  (Jun 23, 2005 to Jun 20, 2006)

3E2E5E  (May 12, 2004 to Jun 20, 2005)

The following publishers (by Authenticode signature organization name) are related.

Remove Visicom Media Inc. Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Visicom Media Inc. by Thawte, Inc. on April 18, 2012 with the serial number '2b19b54bb7abee1a2623111c029af449'.