tmp0000001c37f536f0ff75c94c

Version Update

Visual Tools

The file tmp0000001c37f536f0ff75c94c by Visual Tools has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider.
Publisher:
Visual Tools  (signed and verified)

Product:
Version Update

Version:
1.0.0.1

MD5:
a6a6284e013fbc32c20c49e6ac2a24df

SHA-1:
520ce4e230eaef267ed5dfbe6c916476d56619ba

SHA-256:
f189220449fe0fcb8924736b54687ac62e23f4ebe84bb366bebc599ff3f0b370

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 12:10:29 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Babylon (M)
16.9.26.0

File size:
512 KB (524,288 bytes)

Product version:
1.0.0.1

Copyright:
Copyright © Visual Tools 2014

Original file name:
msp.exe

Language:
English (United States)

Common path:
C:\windows\temp\tmp0000001c37f536f0ff75c94c

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
1/18/2015 10:00:00 PM

Valid to:
1/17/2017 9:59:59 PM

Subject:
CN=Visual Tools, O=Visual Tools, L=Belgrade, S=Serbia, C=RS

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
408E6A1AC8A6BFBB9F655878B36BA3AE

File PE Metadata
Compilation timestamp:
8/30/2015 4:50:02 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:9Chc6n9JDnrEbeXTrp13iFPNp+93djaU1yW4QGn9q4a:9Uc69JLgATrKP3+deMA9q

Entry address:
0xA0DC

Entry point:
E8, 39, 54, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 8B, 45, 08, 56, 8B, F1, 83, 66, 04, 00, C7, 06, C0, A1, 41, 00, C6, 46, 08, 00, FF, 30, E8, A8, 00, 00, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 8B, 45, 08, C7, 01, C0, A1, 41, 00, 8B, 00, 89, 41, 04, C6, 41, 08, 00, 8B, C1, 5D, C2, 08, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, 83, 66, 04, 00, C7, 06, C0, A1, 41, 00, C6, 46, 08, 00, E8, 12, 00, 00, 00, 8B, C6, 5E, 5D, C2, 04, 00, C7, 01, C0, A1, 41, 00, E9, 96, 00, 00, 00, 55, 8B, EC, 56, 57, 8B, 7D, 08...
 
[+]

Code size:
90 KB (92,160 bytes)

Remove tmp0000001c37f536f0ff75c94c - Powered by Reason Core Security