tbuninstall.exe

Toolbar Uninstaller

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application tbuninstall.exe by Visicom Media has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is typically installed with the program VMN Toolbar by Visicom Media Inc. which is a potentially unwanted software program.
Publisher:
Visicom Media Inc.  (signed and verified)

Product:
Toolbar Uninstaller

Version:
1.0.1.5

MD5:
996a311dbbaea3d9300d5e8ebb8711e2

SHA-1:
9f38d3071beaf45f437d8a9ddab9d15d4794b919

SHA-256:
103ff06ae300cf0fa46ebd33d0a3931904adcb65a90608e20ac1ca8883d6b202

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
11/14/2024 2:53:33 PM UTC  (today)

Scan engine
Detection
Engine version

herdProtect (fuzzy)
2015.11.4.4

Panda Antivirus
Suspicious file
15.11.04.04

Reason Heuristics
PUP.Visicom.VisicomMedia.Installer (M)
15.9.9.12

File size:
67 KB (68,568 bytes)

Copyright:
© Visicom Media Inc.

Trademarks:
Dynamic Toolbar, All Rights Reserved

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\Program Files\vmntoolbar\tbuninstall.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
6/20/2007 2:00:00 AM

Valid to:
6/23/2008 1:59:59 AM

Subject:
CN=Visicom Media Inc., OU=SECURE APPLICATION DEVELOPMENT, O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
53647B50983ED1EB11C279CB398C2CA4

File PE Metadata
Compilation timestamp:
4/27/2007 9:59:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:GzVmz/J+Oku5zR+QmJHkFHgGIvFTOM1AqZHmitJX9tSzn4P:eYUOXr+QmJEtgp9OM1ACrtbtSznm

Entry address:
0x32FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 70, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 53, FF, 15, 78, 72, 40, 00, A3, D4, 3F, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, E8, F4, 41, 00, FF, 15, 54, 71, 40, 00, 68, 2C, 92, 40, 00, 68, 20, 37, 42, 00, E8, 9A, 27, 00, 00, FF, 15, B4, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 88, 27, 00, 00, 53, FF, 15, 08, 71, 40, 00, 80, 3D, 00, 90, 42, 00, 22, A3, 20, 3F, 42, 00, 8B, C7, 75, 0A...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file tbuninstall.exe has been discovered within the following program.

VMN Toolbar  by Visicom Media Inc.
The VMN Toolbar is a Visicom toolbar installed in your Web browser that collects and stores information about your web browsing habits and sends this information to Visicom so they can suggest services or provide ads via the toolbar.
software.visicommedia.com
78% remove it
 
Powered by Should I Remove It?

Remove tbuninstall.exe - Powered by Reason Core Security