mcvidrv.sys

ManyCam Virtual Webcam

ManyCam (VISICOM MÉDIA INC.)

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The file mcvidrv.sys, “ManyCam Virtual Webcam Driver” by ManyCam (VISICOM MÉDIA INC.) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Visicom Media Inc.  (signed by ManyCam (VISICOM MÉDIA INC.))

Product:
ManyCam Virtual Webcam

Description:
ManyCam Virtual Webcam Driver

Version:
5.0.3.0

MD5:
c28b0f40b8ea31f9965e2eeb83efcfe3

SHA-1:
7822fa6ccb392e00759a29ee5f7311594af84c39

SHA-256:
adba3a274ddfc5826815c318687fbab3f1304d7941fb78c9bb52aac903205d97

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 12:00:07 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Visicom
17.3.13.21

File size:
47.9 KB (49,064 bytes)

Product version:
5.0.3.0

Copyright:
(c) 2006-2016 Visicom Media Inc.

Original file name:
mcvidrv.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Program Files\manycam\drivers\video\mcvidrv.sys

Digital Signature
Authority:
Symantec Corporation

Valid from:
3/1/2016 7:00:00 AM

Valid to:
3/2/2019 6:59:59 AM

Subject:
CN=ManyCam (VISICOM MÉDIA INC.), O=ManyCam (VISICOM MÉDIA INC.), L=Brossard, S=Quebec, C=CA, SERIALNUMBER=1145963121, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Quebec, OID.1.3.6.1.4.1.311.60.2.1.3=CA

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA - G2, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
041C319EDA4F5240F1802BA471E11BB9

File PE Metadata
Compilation timestamp:
2/8/2017 4:58:07 PM

OS version:
6.3

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
12.0

Entry address:
0xC000

Entry point:
8B, FF, 55, 8B, EC, E8, 06, 00, 00, 00, 5D, E9, F0, 65, FF, FF, 8B, FF, 55, 8B, EC, 51, 51, A1, F4, A8, 40, 00, B9, 4E, E6, 40, BB, 85, C0, 74, 04, 3B, C1, 75, 18, 0F, 31, 35, F4, A8, 40, 00, 89, 55, FC, A3, F4, A8, 40, 00, 75, 07, 8B, C1, A3, F4, A8, 40, 00, F7, D0, A3, F0, A8, 40, 00, 8B, E5, 5D, C3, AC, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 2E, C2, 00, 00, 10, 70, 00, 00, D0, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, AE, C3, 00, 00, 34, 70, 00, 00, 9C, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.9466

Code size:
23 KB (23,552 bytes)

Remove mcvidrv.sys - Powered by Reason Core Security