visualbeeclient{adperio}.exe

Visual Software Systems LTD

The application visualbeeclient{adperio}.exe by Visual Software Systems has been detected as a potentially unwanted program by 4 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from www.visualbee.com.
Publisher:
Visual Software Systems LTD  (signed and verified)

MD5:
df833f7e4a4df1816bfcd5a555e4ce60

SHA-1:
b555c735aeef8a4f0c53b73a3083f4ea3fc98155

SHA-256:
23add13356be193fc8653229a5bb57fdc8fea0cb6c4936372e33d3d1d5785865

Scanner detections:
4 / 68

Status:
Potentially unwanted

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
12/25/2024 2:22:35 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Toolbar.146
9.0.1.0145

ESET NOD32
Win32/Toolbar.Babylon
9.9177

Reason Heuristics
Win32.Generic.Installer.Meta
15.5.25.14

Trend Micro House Call
TROJ_GEN.F47V0926
7.2.145

File size:
1017 KB (1,041,392 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\visualbeeclient{adperio}.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
8/6/2012 7:00:00 PM

Valid to:
10/17/2012 6:59:59 PM

Subject:
CN=Visual Software Systems LTD, O=Visual Software Systems LTD, L=Tel-Aviv, S=Tel-Aviv, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
4B7CEA5C5E19A751EAC2DB7A32D00AAE

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:EZfmfvReae6Sfre/uCGXo6g9XB6rud/PltEtA8e:Mfm3EDrLCSE9XcrudXlYA8e

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9881

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file visualbeeclient{adperio}.exe has been seen being distributed by the following URL.

Remove visualbeeclient{adperio}.exe - Powered by Reason Core Security