gomplayerensetup_2.26.exe

Innovative Systems LLC

The application gomplayerensetup_2.26.exe by Innovative Systems has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from gom-player.joydownload.com.
Publisher:
Innovative Systems LLC  (signed and verified)

MD5:
73411c77262112bf1f1b8fa6ee6c11ba

SHA-1:
56ea2b20035e4dacc357272fa85e113a3fa666df

SHA-256:
41943dcc02585d4debf72681f92ed8c4e2fe0abb0a5f67575dab3b19eed4c961

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/27/2024 3:10:44 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.182.180

AVG
Generic
2016.0.3167

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.15317

Comodo Security
ApplicUnwnt
19585

ESET NOD32
Win32/InstallCore.RA (variant)
9.10654

Fortinet FortiGate
Riskware/InstallCore
3/17/2015

herdProtect (fuzzy)
2015.6.23.15

Qihoo 360 Security
Win32/Virus.Adware.f22
1.0.0.1015

Reason Heuristics
PUP.Installer.InnovativeSystems
15.3.17.18

Sophos
Generic PUA FG
4.98

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
34424

File size:
774.2 KB (792,784 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\gomplayerensetup_2.26.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/18/2014 7:30:00 PM

Valid to:
5/19/2015 7:29:59 PM

Subject:
CN=Innovative Systems LLC, O=Innovative Systems LLC, L=Dnepropetrovsk, S=Dnepropetrovska oblast, C=UA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
450EACFE8D673E82864CE46BC1A92FCA

File PE Metadata
Compilation timestamp:
6/19/1992 5:52:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:HnFWsX2hqUkPmrj6PLx+K4WpOTwHHG8dD:HFnsqUem/Cd+SXHHGE

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file gomplayerensetup_2.26.exe has been seen being distributed by the following URL.

Remove gomplayerensetup_2.26.exe - Powered by Reason Core Security