vopackage.exe

The application vopackage.exe has been detected as adware by 2 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. This file is typically installed with the program Remote Desktop Access (VuuPC) by CMI Limited which is a potentially unwanted software program. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.2ndrequest.me and multiple other hosts. While running, it connects to the Internet address dl21.clickmein.com on port 80 using the HTTP protocol.
Description:
install

Version:
1.0.0.0

MD5:
d0b04bc0bd3550d136d307eca7fbf9f8

SHA-1:
a7a5976c94e9a99cf078f3a0808944df26576488

SHA-256:
733b9fd391099fa4d7cf1bd91b0021a38cf14935f842ef1f448e9290f37de41a

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
4/23/2024 2:53:35 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.CMI.J
14.10.31.9

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.141029

File size:
274.9 KB (281,459 bytes)

Product version:
1.0.0.0

Copyright:
(C) 2014

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\vopackage.exe

File PE Metadata
Compilation timestamp:
12/6/2009 8:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:ke34dztw9RMnMbc75+ZPPfnE2Qyn2FEtt2NB6+sETEtt2NB6+szm:6ztw9iMgF+ZPPfnEUnsEWfXs0EWfXszm

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8758

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file vopackage.exe has been discovered within the following program.

Developed and distributed through bundled installer from Click Me In. The software may be bundled by 3rd-party products using the InstallCore distribution platform.
vuupc.com/terms.html
About 82% of users remove it
 
Powered by Should I Remove It?

The file vopackage.exe has been seen being distributed by the following 2 URLs.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-23-21-114-184.compute-1.amazonaws.com  (23.21.114.184:80)

TCP (HTTP):
Connects to dl21.clickmein.com  (216.227.128.186:80)

Remove vopackage.exe - Powered by Reason Core Security