acehtmlfreeware.exe

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application acehtmlfreeware.exe by Visicom Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer.
Publisher:
Visicom Media Inc.  (signed and verified)

MD5:
b8da31cd9bcc89c20a28fc6000b3468c

SHA-1:
c3c8dec99c0e2df7ac4a39a53cb5825bcfdfb67a

SHA-256:
725f17235ceb4a39db20b708817f71a32b4a1db8681dc5fb9a9d2b9f2c3539a8

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/14/2024 3:00:15 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Visicom.VisicomMedia.Installer (M)
16.1.22.9

File size:
5.7 MB (6,010,672 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\tools\acehtmlfreeware.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
5/30/2006 8:00:00 PM

Valid to:
6/21/2007 7:59:59 PM

Subject:
CN=Visicom Media Inc., OU=SECURE APPLICATION DEVELOPMENT, O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
46009F112341EB9E47AD9A71D868DC95

File PE Metadata
Compilation timestamp:
4/27/2007 3:59:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:z3YrvPRzicv5NkJEQbItAyV+ahSi9pkmhhpNeKyTr9r1EAIMi6JqqV0iW3B+vODd:zorkcvzkJdBL5i9ph0KA5EARiEZlW3Bf

Entry address:
0x3161

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 53, FF, 15, 78, 72, 40, 00, A3, B4, 3F, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, C8, F4, 41, 00, FF, 15, 54, 71, 40, 00, 68, C8, 91, 40, 00, 68, 00, 37, 42, 00, E8, 82, 27, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 70, 27, 00, 00, 53, FF, 15, 08, 71, 40, 00, 80, 3D, 00, 90, 42, 00, 22, A3, 00, 3F, 42, 00, 8B, C7, 75, 0A...
 
[+]

Entropy:
7.9995

Packer / compiler:
Nullsoft install system v2.x

Code size:
22 KB (22,528 bytes)

Remove acehtmlfreeware.exe - Powered by Reason Core Security