mediaplayerclassic.exe

The application mediaplayerclassic.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a setup program which is used to install the application. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from i.vertitechnologygroup.com.
MD5:
7ae7af8d6b8447ecebe16da8764f9c58

SHA-1:
3abaf268e995bf3cc4751d98f5111ed3466bc52a

SHA-256:
c94e7b0ae391ab1dd26ebaef5eb8e6485fe00e4c763bba7af048149673eecb7e

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 11:26:51 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.G
961

Bitdefender
Application.Bundler.G
1.0.20.850

Dr.Web
Adware.Downware.4150
9.0.1.05190

F-Secure
Application.Bundler.G
11.2014-19-06_5

G Data
Application.Bundler
14.6.24

MicroWorld eScan
Application.Bundler.G
15.0.0.510

NANO AntiVirus
Riskware.Win32.Downware.czxoaw
0.28.0.60253

VIPRE Antivirus
Threat.4786530
29708

File size:
364.6 KB (373,308 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\mediaplayerclassic.exe

File PE Metadata
Compilation timestamp:
5/13/2014 7:23:58 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:iKk02wQjZnnUAHlESM9Pt/IBP4BoHg8dqqkSyorKv8AO9ALqE1cxfro7zF1W+LVo:iL02dncz9F/IBABoHVLvPbALqE1cxfrb

Entry address:
0x22009

Entry point:
E8, 46, A7, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 90, 10, 45, 00, 33, C5, 89, 45, FC, 83, 7D, 08, FF, 57, 74, 09, FF, 75, 08, E8, D1, 85, 00, 00, 59, 83, A5, E0, FC, FF, FF, 00, 6A, 4C, 8D, 85, E4, FC, FF, FF, 6A, 00, 50, E8, 93, B3, FF, FF, 8D, 85, E0, FC, FF, FF, 89, 85, D8, FC, FF, FF, 8D, 85, 30, FD, FF, FF, 83, C4, 0C, 89, 85, DC, FC, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC...
 
[+]

Code size:
218.5 KB (223,744 bytes)

The file mediaplayerclassic.exe has been seen being distributed by the following URL.

Remove mediaplayerclassic.exe - Powered by Reason Core Security