ToolbarCleaner.exe

Toolbar Cleaner

Lavasoft Limited

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application ToolbarCleaner.exe by Lavasoft Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Visicom Media Inc.  (signed by Lavasoft Limited)

Product:
Toolbar Cleaner

Version:
1, 1, 0, 3

MD5:
53d32ada7c11c7f80db79d08ceebabe6

SHA-1:
d9d8e85f6394d3cdaf9c46cc8b52341289b48813

SHA-256:
6528dad8d33046e847bb7449d47e67ee7701c60e6ec09cfb2b57822afd0eee3c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/28/2024 2:16:33 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Visicom.Toolbar
17.2.17.0

File size:
568.9 KB (582,552 bytes)

Product version:
1, 1, 0, 3

Copyright:
Copyright (c) 2012 All rights reserved Visicom Media Inc.

Original file name:
ToolbarCleaner.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\toolbar cleaner\toolbarcleaner.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/28/2011 2:00:00 AM

Valid to:
1/28/2013 1:59:59 AM

Subject:
CN=Lavasoft Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Lavasoft Limited, L=Sliema, S=SLM, C=MT

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7CEC887E3A0E10A63F47C72B25751AB9

File PE Metadata
Compilation timestamp:
6/14/2012 5:03:16 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x419E1

Entry point:
E8, 6B, EA, 00, 00, E9, 79, FE, FF, FF, CC, 68, 10, 09, 44, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 80, 31, 47, 00, 31, 45, FC, 33, C5, 89, 45, E4, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, E4, 33, CD, E8, 39, B4, FF, FF, E9, B2, EE, FF, FF, 6A, 0C, 68, A0, DF, 46, 00, E8, 61, EE, FF, FF, 6A, 0E, E8, 7B, 41, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04...
 
[+]

Entropy:
6.4373

Code size:
363.5 KB (372,224 bytes)

Remove ToolbarCleaner.exe - Powered by Reason Core Security