manydownloader32.free.exe

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application manydownloader32.free.exe by Visicom Media has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.manydownloader.com.
Publisher:
Visicom Media Inc.  (signed and verified)

Version:
1.5.1.155

MD5:
ada2f27007bc35bcb5b19c6f43299e1c

SHA-1:
489e07e6eba8d06d4caf0f081dc0f0ddd08a8e7b

SHA-256:
f3a77711155b77d3d700e47ce1f5ceb96110aa085d515902cd8279d88cffdf1d

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 4:34:47 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Toolbar.272
9.0.1.0154

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.Visicom.VisicomMedia
15.6.3.20

File size:
18.4 MB (19,307,272 bytes)

Product version:
1.5.1.155

Copyright:
© 2013-2014 Visicom Media Inc.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\manydownloader32.free.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
5/7/2014 8:00:00 PM

Valid to:
6/20/2016 7:59:59 PM

Subject:
CN=Visicom Media Inc., OU=SECURE APPLICATION DEVELOPMENT, O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
266F9E30991B0C3EFC03DA9B8CDDB68D

File PE Metadata
Compilation timestamp:
9/17/2014 10:45:18 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
393216:obNvVLpBVwnVB6hSy+8hSXp2ob9Dj7WV4ess1qpCjMLcIUj:obnXiVB6S1Xp2okeeSpuj

Entry address:
0x3D50

Entry point:
E8, D6, 2A, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, 0D, 03, 00, 00, 3B, 0D, 54, 01, 42, 00, 75, 02, F3, C3, E9, 4D, 2B, 00, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 56, 8B, F1, C6, 46, 0C, 00, 85, C0, 75, 63, E8, 99, 27, 00, 00, 89, 46, 08, 8B, 48, 6C, 89, 0E, 8B, 48, 68, 89, 4E, 04, 8B, 0E, 3B, 0D, 68, 07, 42, 00, 74, 12, 8B, 0D, 84, 06, 42, 00, 85, 48, 70, 75, 07, E8, A5, 35, 00, 00, 89, 06, 8B, 46, 04, 3B, 05, 88, 05, 42, 00, 74, 16, 8B, 46, 08, 8B, 0D, 84, 06, 42, 00, 85, 48, 70, 75, 08, E8...
 
[+]

Entropy:
7.9990  (probably packed)

Code size:
84.5 KB (86,528 bytes)

The file manydownloader32.free.exe has been seen being distributed by the following URL.

Remove manydownloader32.free.exe - Powered by Reason Core Security