avimediaplayersetup.exe

AVI Media Player

vsevensoft.com

The application avimediaplayersetup.exe, “AVI Media Player Setup ” has been detected as a potentially unwanted program by 11 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. Part of RelevantKnowledge, a program typically installed via a software bundle (with the user's knowledge should they read the EULA) and will run in the background collecting and monitoring information about the user's behavior in order to build an extensive profile.
Publisher:
vsevensoft.com

Product:
AVI Media Player

Description:
AVI Media Player Setup

Version:
1.0

MD5:
021d81b77076291743b019ac59089f7c

SHA-1:
1ecd0229e0d43a10cb0f715addffcb9de9465ed1

SHA-256:
262c52e9f68f91554c3d5a562defeb693affea7f9d026dbbce13afa66d9a2a3e

Scanner detections:
11 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 1:22:36 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Spyware.Relevantknowledge.A
623

avast!
Win32:Relevant-P [PUP]
2014.9-150523

AVG
RelevantKnowledge
2016.0.3101

Dr.Web
Adware.Downware.10962
9.0.1.0143

ESET NOD32
Win32/Complitly.A potentially unwanted (variant)
9.11618

Malwarebytes
PUP.Adware.RKN
v2015.05.23.11

MicroWorld eScan
Spyware.Relevantknowledge.A
16.0.0.429

NANO AntiVirus
Trojan.Win64.Searcher.ctuoay
0.30.24.1357

Qihoo 360 Security
Win32/Trojan.Spy.0b9
1.0.0.1015

Trend Micro House Call
Suspicious_GEN.F47V0308
7.2.143

VIPRE Antivirus
Trojan.Win32.Generic
40192

File size:
5.9 MB (6,232,709 bytes)

Product version:
1.0

Copyright:
Copyright (c) 2009 vsevensoft.com

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\avimediaplayersetup.exe

File PE Metadata
Compilation timestamp:
6/10/2010 4:33:52 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:fk0g77B8GKvplBZxpPJD/iaCLFBZG4no5sgjgUdTQ/3/VPbWYAtwAq/Nu1NoDeT9:fk0g/9EplBPpPZ/iXLFB042jNTQ/3/Bs

Entry address:
0x163C4

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 54, 55, 41, 00, E8, 70, 04, FF, FF, 33, C0, 55, 68, 91, 6A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 4D, 6A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, A6, EF, FF, FF, E8, B1, EA, FF, FF, 8D, 55, EC, 33, C0, E8, FB, 87, FF, FF, 8B, 55, EC, B8, A8, D6, 41, 00, E8, A6, EA, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, A8, D6, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
85 KB (87,040 bytes)

Remove avimediaplayersetup.exe - Powered by Reason Core Security