mediaplayer.exe

The application mediaplayer.exe has been detected as a potentially unwanted program by 12 anti-malware scanners. The file has been seen being downloaded from nym1.ib.adnxs.com.
MD5:
146ec7b1c43f1f422026c3887bf9c943

SHA-1:
1f3aaa81c45c2a67cff5fab588eec3a53272ef70

SHA-256:
3bbf0048c5033cdcea87a8349724eb29b13d808d5e654e48eefef5e58e276bed

Scanner detections:
12 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallIQ (by InstallX) software bundler that may include toolbars and other browser extensions offers.

Analysis date:
4/19/2024 4:04:02 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
MultiBundle
2016.0.3001

Dr.Web
Adware.Searcher.2593
9.0.1.0242

ESET NOD32
Win32/InstallIQ (variant)
9.9530

herdProtect (fuzzy)
2015.8.30.21

Malwarebytes
PUP.Optional.SafeInstall.A
v2015.08.30.09

McAfee
PUP-FLX
5600.6657

NANO AntiVirus
Riskware.Win32.Searcher.csnymk
0.28.0.58101

Reason Heuristics
Threat.Win.Reputation.IMP
15.7.28.7

Rising Antivirus
PE:PUF.InstallIQ!1.9E4F
23.00.65.15828

Sophos
DomainIQ pay-per install
4.98

Trend Micro House Call
TROJ_GEN.F47V0312
7.2.242

VIPRE Antivirus
InstallIQ Installer
27288

File size:
1.6 MB (1,711,720 bytes)

File type:
Executable application (Win16 EXE)

Common path:
C:\users\{user}\downloads\mediaplayer.exe

File PE Metadata
Compilation timestamp:
3/5/2014 11:36:36 AM

OS version:
5.1

OS bitness:
Win16

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:Nr3oVu7M374ZzE33WwT5Fxf8lIKlmPsAo7F+ywTvGVzAPL/zE8hhTukhbTTtsg7m:SHWIVKOocyI+VzA08hl1TZsgMoMRTY1Q

Entry address:
0x4E7ED

Entry point:
E8, F0, 3A, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 80, 98, 52, 00, E8, 2D, 2B, 00, 00, E8, BD, 3C, 00, 00, 0F, B7, F0, 6A, 02, E8, 83, 3A, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 64, 34, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.9549

Code size:
985.5 KB (1,009,152 bytes)

The file mediaplayer.exe has been seen being distributed by the following URL.

Remove mediaplayer.exe - Powered by Reason Core Security