wsetup.exe

SPK

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application wsetup.exe, “Installer Utility” by Visicom Media has been detected as a potentially unwanted program by 4 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from installer.manycams.com.
Publisher:
Visicom Media Inc.  (signed and verified)

Product:
SPK

Description:
Installer Utility

Version:
1.0.0.6

MD5:
47e558a0e06df433d4b1f2943097e7ed

SHA-1:
f983a53c14d3a7b67fc8c2525e3ace21012386c2

SHA-256:
7daf00e936b350e5f8288fa1f300468c46543b42c2de2ece5e6a74a515497ce0

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
9/28/2025 5:38:46 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Tool.InstallToolbar.179
9.0.1.0241

Reason Heuristics
PUP.Visicom.VisicomMedia.Installer (M)
15.8.29.3

Trend Micro House Call
Suspicious_GEN.F47V0429
7.2.241

File size:
95.8 KB (98,056 bytes)

Product version:
1.0.0.6

Copyright:
Copyright (c) 2015 All rights reserved Visicom Media Inc.

Original file name:
spk.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\wsetup.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
5/8/2014 1:00:00 AM

Valid to:
6/21/2016 12:59:59 AM

Subject:
CN=Visicom Media Inc., OU=SECURE APPLICATION DEVELOPMENT, O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
266F9E30991B0C3EFC03DA9B8CDDB68D

File PE Metadata
Compilation timestamp:
2/4/2015 3:08:07 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
768:CMKmTqiMw/s9oy6FsnMLeU39kksfFAfOKPGbxPZU9qZU9+UxkK4sAY:tbguy6FRq5FIOLxPpNQC7Y

Entry address:
0x59A9

Entry point:
E8, DA, 03, 00, 00, E9, 37, FD, FF, FF, CC, FF, 25, DC, 71, 40, 00, CC, CC, 68, 15, 5A, 40, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 1C, A0, 40, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 8B, FF, 55, 8B, EC, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, 68, AE, 54...
 
[+]

Code size:
22.5 KB (23,040 bytes)

The file wsetup.exe has been seen being distributed by the following URL.

Remove wsetup.exe - Powered by Reason Core Security