z_downloader.exe

ZGame Toolbar

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application z_downloader.exe, “ZGame Toolbar Installer” by Visicom Media has been detected as a potentially unwanted program by 7 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer.
Publisher:
Visicom Media Inc.  (signed and verified)

Product:
ZGame Toolbar

Description:
ZGame Toolbar Installer

Version:
2.0

MD5:
00b6a8c35c6a868d53b29cfec94da42e

SHA-1:
e80b63605b21beb33976179f8cf279511cc82fd5

SHA-256:
86c52255ac3ad28b487f231e56ef510e64c8895f4655008dc67f6a1e5c324419

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
The setup program may install a variant of the Visicom Toolbar, a web browser extension that may modify the browser's home and search pages.

Analysis date:
4/20/2024 3:44:47 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Tool.InstallToolbar.129
9.0.1.0351

ESET NOD32
Win32/Toolbar.Visicom (variant)
7.9183

K7 AntiVirus
Trojan
13.174.10538

McAfee
Artemis!00B6A8C35C6A
5600.7278

Reason Heuristics
PUP.ZGameToolbarInstaller.VisicomMedia.M
14.10.1.11

Trend Micro House Call
TROJ_GE.DAB0F271
7.2.351

VIPRE Antivirus
Trojan.Win32.Generic!SB.0
24456

File size:
2.5 MB (2,600,664 bytes)

Product version:
2.0.0.1

Copyright:
© Visicom Media Inc. (License)

Trademarks:
Visicom Media Inc., All Rights Reserved

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\z_downloader.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
4/18/2012 8:00:00 AM

Valid to:
6/22/2014 7:59:59 AM

Subject:
CN=Visicom Media Inc., OU=SECURE APPLICATION DEVELOPMENT, O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2B19B54BB7ABEE1A2623111C029AF449

File PE Metadata
Compilation timestamp:
12/6/2009 6:50:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:h1PPQEARBrKbMEvpR45+R/GrH00H3TRZ1av42mNfyG0ApTjqBtLhW9:h1PPTA32oEE5Lg0H3TIv4XEG5ADU

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9636

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file z_downloader.exe has been seen being distributed by the following 11 URLs.

temp:z_downloader (1).exe

temp:z_downloader.exe

temp:z_downloader-1.exe

Remove z_downloader.exe - Powered by Reason Core Security