hmplayer.exe

Haihaisoft Universal Player

Haihaisoft Corporation

The executable hmplayer.exe has been detected as malware by 12 anti-virus scanners.
Publisher:
Haihaisoft  (signed by Haihaisoft Corporation)

Product:
Haihaisoft Universal Player

Version:
1.3.4.0

MD5:
970c639e967cdb1758311a40685d7223

SHA-1:
6f919d67c41711b4d5349236379364f5da3a9ea2

SHA-256:
84f38ae416f17740e66c278016418ed5baeba77e0d35272e05efaa1ee3223c95

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
4/25/2024 8:06:29 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Pioneer-C
160518-2

AVG
Win32/Floxif.A
2015.0.4591

Dr.Web
Win32.FloodFix.7
9.0.1.05190

Emsisoft Anti-Malware
Win32.Floxif
16.06.04

ESET NOD32
Win32/Floxif.H virus
8.0.319.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.15.96

Kaspersky
Virus.Win32.Pioneer
15.0.0.562

McAfee
Trojan.Dropper-FIY!970C639E967C
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.654.0

Norman
Win32.Floxif.A
28.05.2016 15:32:18

Sophos
Virus 'W32/Floxif-C'
5.23

File size:
4.3 MB (4,546,207 bytes)

Product version:
1.3.4.0

Copyright:
Copyright (C) 2004-2008 Haihaisoft Co.,Ltd. All rights reserved.

Original file name:
mplayerc.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\haihaisoft universal player\hmplayer.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
3/23/2009 6:00:00 AM

Valid to:
3/24/2011 5:59:59 AM

Subject:
CN=Haihaisoft Corporation, O=Haihaisoft Corporation, STREET="Room 301, No.61, No.666 of Longdong Rd", L=Shanghai, S=Shanghai, PostalCode=201203, C=CN

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00869E70F356CAE660B3EE1526D97FCDB8

File PE Metadata
Compilation timestamp:
4/6/2009 11:37:04 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:nVTR4PiKlfX4Ak3xYHQ5MJG0MpQFl5cs+lzamVqIARzAXos3wcYM1dYoUAxdEZCt:nrTI4oQ5MM0hl5cs+lzamVqIARzAXosT

Entry address:
0x2889E0

Entry point:
E9, 48, 91, E0, FF, E9, 17, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, A7, B9, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, CE, 2B, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, BE, 15, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 2D, 15, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73, 0E, E8, 58, B9, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, AD, 6A, 16...
 
[+]

Entropy:
6.6106

Packer / compiler:
Xtreme-Protector v1.05

Code size:
2.8 MB (2,985,984 bytes)

Autoplay Handler
Display name:
MPCPlayCDAudioOnArrival


Remove hmplayer.exe - Powered by Reason Core Security