installer_mediaplayer_spanish.exe

Vittalia Limited

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application installer_mediaplayer_spanish.exe by Vittalia Limited has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer.
Publisher:
Vittalia Limited  (signed and verified)

MD5:
d48d19fd1fa52072dae73164efce1761

SHA-1:
6d4782389902ec85c9b402b1c2b014372e6f057a

SHA-256:
488d97486926d2f269605beadaa9d10fd3a1f5535c67ef5ef53e5524b5de6c36

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/19/2024 3:54:05 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
APPL/Downloader.Gen9
7.11.170.52

AVG
Adware BundleApp_r.O
2014.0.4015

Comodo Security
TrojWare.Win32.Agent.IEXT
19383

Dr.Web
Trojan.Packed.26758
9.0.1.05190

ESET NOD32
Win32/Vittalia.Q potentially unwanted application
7.0.302.0

IKARUS anti.virus
PUA.Vittalia
t3scan.1.7.5.0

Malwarebytes
PUP.Optional.Vittalia
v2014.09.01.01

Reason Heuristics
PUP.VittaliaLimited.DD
14.9.2.22

Sophos
Vittalia
4.98

VIPRE Antivirus
Threat.4782551
32210

File size:
4.6 MB (4,873,840 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Common path:
C:\users\{user}\downloads\installer_mediaplayer_spanish.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/17/2013 8:00:00 PM

Valid to:
5/17/2016 7:59:59 PM

Subject:
CN=Vittalia Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Vittalia Limited, L=Dublin, S=Dublin, C=IE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6CC8DB30E67B3DF9E2607EE882D390AC

File PE Metadata
Compilation timestamp:
5/16/2014 6:02:57 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:CdbWz+zHlr20RHVZw3S4SI/r9Aa2pyZn2WlqwTo6usOouOcA24b/K:cWuH

Entry address:
0x1E28B

Entry point:
E8, E5, A7, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, E0, 1A, 44, 00, E8, EF, 40, 00, 00, E8, 60, 37, 00, 00, 0F, B7, F0, 6A, 02, E8, 78, A7, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 9A, 72, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.3672

Code size:
202.5 KB (207,360 bytes)

Remove installer_mediaplayer_spanish.exe - Powered by Reason Core Security