tmp00000004c6e92373ea3a2499

Anti-phishing Domain Advisor

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The file tmp00000004c6e92373ea3a2499, “Visicom Media Anti-phishing Domain Advisor (Powered by Panda Security)” by Visicom Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Visicom Media Inc. (Powered by Panda Security)  (signed by Visicom Media Inc.)

Product:
Anti-phishing Domain Advisor

Description:
Visicom Media Anti-phishing Domain Advisor (Powered by Panda Security)

Version:
1, 0, 1, 31

MD5:
d39f4e108eec8b8e87035f8a681478b9

SHA-1:
cf9af88819084e38516e36ff5b5991cdda388cc7

SHA-256:
2003fa13ed75c0c3682dce35cd16e2cb5a9a4b97f882ae04a7ef7370afb4ebeb

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/16/2024 7:31:15 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Visicom (M)
17.2.14.17

File size:
512 KB (524,288 bytes)

Product version:
1.0

Copyright:
Copyright (C) 2010 Visicom Media Inc.

Language:
English (United States)

Common path:
C:\windows\temp\tmp00000004c6e92373ea3a2499

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
6/24/2010 2:00:00 AM

Valid to:
6/22/2012 1:59:59 AM

Subject:
CN=Visicom Media Inc., OU=SECURE APPLICATION DEVELOPMENT, O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
73C74D9445094BFD79759F7B9CAFD730

File PE Metadata
Compilation timestamp:
12/21/2011 11:48:39 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

Entry address:
0x2D07F

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 33, 70, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32...
 
[+]

Entropy:
4.3898

Code size:
225 KB (230,400 bytes)

Remove tmp00000004c6e92373ea3a2499 - Powered by Reason Core Security