xmph.dll

CrossMediaExperience

VoiceFive, Inc.

The component is part of the TMRG platform which will track various behaviors of web browsing habits including tracking sites and domains visited as well as ads clicked. The module xmph.dll by VoiceFive has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
VoiceFive Networks, Inc.  (signed by VoiceFive, Inc.)

Product:
CrossMediaExperience

Version:
1.0.1.8

MD5:
6651bf3e775f7927a4fb69ab66230867

SHA-1:
2d470864f957c7b60ee8e3d5eaecd4ca5b42ce18

SHA-256:
52a463f2017f4303ccd70ef229481547bdec9e8075be79087f94b74e5e9d7841

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/2/2024 11:32:20 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.TMRG (M)
16.10.3.7

File size:
801 KB (820,248 bytes)

Product version:
1.0.1.8

Copyright:
Copyright (C) 2007-2011

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\crossmediaexperience\xmph.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
9/27/2011 7:00:00 PM

Valid to:
9/27/2013 6:59:59 PM

Subject:
CN="VoiceFive, Inc.", O="VoiceFive, Inc.", L=Reston, S=Virginia, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3EDFC5EA7AAD2A20B9C31AE68DC1005C

File PE Metadata
Compilation timestamp:
9/12/2011 4:41:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:K9VZRG3DDOEM3/auz7iMpAxHeoHVMSe60zceEh:8VZRODGhZa1eoHVMSGEh

Entry address:
0x5C23C

Entry point:
83, 7C, 24, 08, 01, 75, 05, E8, DE, E0, 00, 00, FF, 74, 24, 04, 8B, 4C, 24, 10, 8B, 54, 24, 0C, E8, ED, FE, FF, FF, 59, C2, 0C, 00, 8B, 44, 24, 04, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8, F6, B5, FF, FF, 59, C3, 55, 8B, EC, 83, EC, 14, A1, C0, 7D, 0B, 10, 33, C5, 89, 45, FC, 53, 56, 33, DB, 39, 1D, 3C, 9D, 0B, 10, 57, 8B, F1, 75, 38, 53, 53, 33, FF, 47, 57, 68, AC, 7C, 08, 10, 68, 00, 01, 00, 00, 53, FF, 15, 8C, B0, 07, 10, 85, C0, 74, 08, 89, 3D, 3C, 9D, 0B, 10, EB, 15, FF, 15...
 
[+]

Entropy:
6.4037

Code size:
488 KB (499,712 bytes)

Remove xmph.dll - Powered by Reason Core Security