game-player-7.0.265-setup.exe

Game Player 7.0.265

TRACERMM SOFT SOLUTIONS

The application game-player-7.0.265-setup.exe, “Game Player 7.0.265 Setup ” has been detected as a potentially unwanted program by 7 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.download3k.com and multiple other hosts.
Publisher:
TRACERMM SOFT SOLUTIONS

Product:
Game Player 7.0.265

Description:
Game Player 7.0.265 Setup

MD5:
67bc76700ac9b1482ae647256e2df0ac

SHA-1:
098c2d6c5713646d90d23ea7e951781bc3c56099

SHA-256:
b76b2c0530e1bd0bb423b8aa00a4275c1b52fb24bed8ee2d78fffb01de6012c9

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/19/2024 3:57:08 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Hacktool.Win32.Squnsh
4.0.3.15910

Dr.Web
Adware.InstallCore.53
9.0.1.0253

ESET NOD32
Win32/DownWare.W potentially unwanted
9.11568

F-Prot
W32/HackTool.DBS
v6.4.7.1.166

IKARUS anti.virus
not-a-virus:RiskTool.Win32.Squnsh
t3scan.1.8.9.0

Kaspersky
not-a-virus:RiskTool.Win32.Squnsh
14.0.0.1448

NANO AntiVirus
Riskware.Win32.HackTool.xwxdc
0.30.24.1357

File size:
1.5 MB (1,599,939 bytes)

Product version:
7.0.265

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\game-player-7.0.265-setup.exe

File PE Metadata
Compilation timestamp:
6/20/1992 3:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:1nvtk8DdXI11z/5fclB3QDiPbxqF98bm29ZyaLWDzxZpAiEB8p9IKULRyorygRsZ:1v6kXITz/RcbgU08t9LWHgQIKa/PS

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9913

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file game-player-7.0.265-setup.exe has been seen being distributed by the following 2 URLs.

http://www.download3k.com/DownloadLink1-Game-Player-7.0.200.html

Remove game-player-7.0.265-setup.exe - Powered by Reason Core Security