dlsecuretb_1.5.0.1.exe

DLSecure Toolbar

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application dlsecuretb_1.5.0.1.exe, “DLSecure Toolbar Installer” by Visicom Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software.
Publisher:
Visicom Media Inc.  (signed and verified)

Product:
DLSecure Toolbar

Description:
DLSecure Toolbar Installer

Version:
1.5

MD5:
3c27151149894e13042d736f0c411ee3

SHA-1:
dcc46743914116fb372bc78f1d5e218d11d00ceb

SHA-256:
deb4c91a2047b64ac0e2a53c1db940086b8be8cc4a533d18d83095fccc69493e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/14/2024 7:55:16 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Visicom (M)
17.3.16.7

File size:
4.5 MB (4,741,571 bytes)

Product version:
1.5.0.1

Copyright:
© Visicom Media Inc. (License)

Trademarks:
Visicom Media Inc., All Rights Reserved

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\dlsecuretb_1.5.0.1.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/9/2015 1:00:00 AM

Valid to:
2/9/2017 12:59:59 AM

Subject:
CN=Visicom Media Inc., OU=Visicom Media Inc., O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
0F7022688814C950B353E71B8D1C1D84

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x323C

Entry point:
60, E8, 00, 00, 00, 00, 5B, 81, EB, D0, 48, 8F, 01, 83, EC, 74, 8B, EC, 8B, 83, AB, 4B, 8F, 01, 89, 45, 00, 8B, 83, B3, 4B, 8F, 01, 03, 45, 00, 89, 45, 2C, 8B, 83, B7, 4B, 8F, 01, 03, 45, 00, 89, 45, 30, C7, 45, 14, 00, 00, 00, 00, C7, 45, 18, 00, 00, 00, 00, C7, 45, 1C, 00, 00, 00, 00, 8B, 45, 14, FF, 45, 14, 66, 33, C9, 8A, 8C, 03, FF, 4B, 8F, 01, 84, C9, 74, 7A, 8B, 45, 1C, 66, 01, 4D, 1C, 03, C3, 05, 13, 4C, 8F, 01, 50, 8B, 45, 2C, FF, 10, 85, C0, 0F, 84, 5E, 02, 00, 00, 89, 45, 10, 8B, 45, 1C, 03, C3...
 
[+]

Packer / compiler:
ASPack v1.08.04

Code size:
23 KB (23,552 bytes)

Remove dlsecuretb_1.5.0.1.exe - Powered by Reason Core Security