mystart_one_installer.exe

MyStart One

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application mystart_one_installer.exe, “MyStart One Installer” by Visicom Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory.
Publisher:
Visicom Media Inc.  (signed and verified)

Product:
MyStart One

Description:
MyStart One Installer

Version:
1.0.0.17

MD5:
7cd0459dd6c55bb19d4e66a5674fcf0f

SHA-1:
e75f1a61dbb7f97039ea92a6fa47b08cc906923c

SHA-256:
f99602013dd860d299825318eeb946805ebbfac63530a90d87da063b53ae43e5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/14/2024 3:05:34 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Visicom.Installer
16.10.25.19

File size:
321.8 KB (329,552 bytes)

Product version:
1.0.0.17

Copyright:
Copyright 1996-2016 Visicom Media Inc.

Trademarks:
MyStart One is a trademark of Visicom Media Inc.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\mystart_one_installer.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/23/2016 9:00:00 PM

Valid to:
5/24/2018 8:59:59 PM

Subject:
CN=Visicom Media Inc., O=Visicom Media Inc., STREET=6200 boul Taschereau bureau 304, L=brossard, S=QC, PostalCode=j4w3j8, C=CA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E25AF4332B02B92A0E6930E09FF597C2

File PE Metadata
Compilation timestamp:
12/5/2009 8:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:6e34XQHhbInyfHDOOXxdcIgAOTo2n4qAz7SmDkUn:QSWnkH/xaIUTf4qAz7S5Un

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove mystart_one_installer.exe - Powered by Reason Core Security