uninstall.exe

MyStart Toolbar

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application uninstall.exe, “MyStart Toolbar Uninstaller” by Visicom Media has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program MyStart Toolbar by Visicom Media Inc..
Publisher:
Visicom Media Inc.  (signed and verified)

Product:
MyStart Toolbar

Description:
MyStart Toolbar Uninstaller

Version:
5.4

MD5:
62fd191c4edcaf1870b096576a62f00c

SHA-1:
73247bdfaf266d0715dd6321077ada349672a613

SHA-256:
4f84feebdf96aaa63bad2caa97cbde01d650e3c152103387c02e5ee906164af5

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 3:03:10 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Visicom
2017.0.2862

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Trojan.Agent-751031
0.98/21411

Dr.Web
Adware.Toolbar.272
9.0.1.016

Reason Heuristics
PUP.Visicom.VisicomMedia.Installer (M)
16.1.16.17

Trend Micro House Call
Suspicious_GEN.F47V0702
7.2.16

File size:
409 KB (418,824 bytes)

Product version:
5.4.6.10

Copyright:
© Visicom Media Inc. (License)

Trademarks:
Visicom Media Inc., All Rights Reserved

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\Program Files\mystarttb\uninstall.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
5/7/2014 8:00:00 PM

Valid to:
6/20/2016 7:59:59 PM

Subject:
CN=Visicom Media Inc., OU=SECURE APPLICATION DEVELOPMENT, O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
266F9E30991B0C3EFC03DA9B8CDDB68D

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:GfnrXQt8G1o9162lt89Zi2GQTIOeUNyjtN2BN5ew:0rgt8h9MijueVjGj5r

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9363

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Program Uninstaller
Program name:
MyStart Toolbar

Display publisher:
Visicom Media Inc.

Display version:
5.4.6.10

Uninstall string:
C:\Program Files (x86)\mystarttb\uninstall.exe


Remove uninstall.exe - Powered by Reason Core Security