twc-tb-ie-1111.exe

Time Warner Cable Enterprises LLC

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application twc-tb-ie-1111.exe by Time Warner Cable Enterprises has been detected as adware by 2 anti-malware scanners. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.timewarnercable.com.
Publisher:
Visicom Media Inc.  (signed by Time Warner Cable Enterprises LLC)

Version:
1, 0, 0, 20

MD5:
cf391efa39d25c798619a8b9273b0ce4

SHA-1:
a7427442e340a71f0224234949050801eb2c6789

SHA-256:
848a05f53d6fb15d06600a05a2da9ea5311d113fd119011fc796d078b4c852e6

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
8/18/2025 1:26:26 AM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM41.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Win32.Generic.Visicom.Meta
15.8.5.1

File size:
319 KB (326,680 bytes)

Product version:
1, 0, 0, 20

Copyright:
© 2013-2014 Visicom Media Inc.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\twc-tb-ie-1111.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
11/30/2014 7:00:00 PM

Valid to:
12/2/2015 6:59:59 PM

Subject:
CN=Time Warner Cable Enterprises LLC, OU=CST, O=Time Warner Cable Enterprises LLC, L=Herndon, S=Virginia, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
62D13CDAB80F4320DF678D1C03876CA3

File PE Metadata
Compilation timestamp:
9/17/2014 10:45:18 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:JldiKb4WhLyGOAkzfnM06pw3daNpY2/fz/U6anLO6:JldRbdjAVAw3SzcNO6

Entry address:
0x3D50

Entry point:
E8, D6, 2A, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, 0D, 03, 00, 00, 3B, 0D, 54, 01, 42, 00, 75, 02, F3, C3, E9, 4D, 2B, 00, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 56, 8B, F1, C6, 46, 0C, 00, 85, C0, 75, 63, E8, 99, 27, 00, 00, 89, 46, 08, 8B, 48, 6C, 89, 0E, 8B, 48, 68, 89, 4E, 04, 8B, 0E, 3B, 0D, 68, 07, 42, 00, 74, 12, 8B, 0D, 84, 06, 42, 00, 85, 48, 70, 75, 07, E8, A5, 35, 00, 00, 89, 06, 8B, 46, 04, 3B, 05, 88, 05, 42, 00, 74, 16, 8B, 46, 08, 8B, 0D, 84, 06, 42, 00, 85, 48, 70, 75, 08, E8...
 
[+]

Entropy:
6.9759

Code size:
84.5 KB (86,528 bytes)

The file twc-tb-ie-1111.exe has been seen being distributed by the following URL.

Remove twc-tb-ie-1111.exe - Powered by Reason Core Security