player-chrome.exe

Boot Compute

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application player-chrome.exe, “Fusion Install ” by Boot Compute has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Adknowledge Fusion installer. With this installer, users are expecting to download Google's Chrome web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Fusion Install   (signed by Boot Compute)

Product:
Fusion Install

Description:
Fusion Install

Version:
2.4.8.1

MD5:
43a9607add9358a049ab2b51225bb950

SHA-1:
455520a63e7ad92e79640590449de4b7b708442a

SHA-256:
892778ff15f36c560c77431135a54ec0eda9afe177209ef5bb298ed6d1a19770

Scanner detections:
1 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/13/2024 1:55:07 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Adknowledge (M)
17.3.14.18

File size:
246.4 KB (252,280 bytes)

Product version:
2.4.8.1

Copyright:
Copyright (C) 2013 Fusion Install

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
English (United States)

Common path:
C:\users\{user}\downloads\player-chrome.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/23/2014 9:00:00 PM

Valid to:
3/24/2015 8:59:59 PM

Subject:
CN=Boot Compute, O=Boot Compute, STREET="4600 Madison Ave, 10th FL", L=Kansas City, S=Missouri, PostalCode=64112, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
059AEF62ABD7F83178378663E98BDE5C

File PE Metadata
Compilation timestamp:
9/17/2014 5:30:25 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1508B

Entry point:
E8, C2, 05, 00, 00, E9, D7, FC, FF, FF, CC, FF, 25, 58, 71, 41, 00, 68, F5, 50, 41, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 1C, C0, 41, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 8B, FF, 55, 8B, EC, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, 68, 36, 4C, 41, 00...
 
[+]

Code size:
87 KB (89,088 bytes)

The file player-chrome.exe has been seen being distributed by the following URL.

http://download1261bucket.com/track/install?gluid=gyaEYiQh4MIYSem0qAaTwdewsALD yqyHrgX3w6Eg7uxatED6X50xeJjGNHUiw/0y5AUiImxnMcPrSeRm3pkHFVKVdTiyptHJIxbnBm8X7ZNaAcH/wflYteD8cjUayK15wnFf fe oq3buxzqvhNWkNo3wHFEVn0p/3ty53PsauCIhuk4LwVQ64 Q1pheYkLj8l9tPp0ehp6VgYroq/du T9c6M7aggGusmLFwrXb9L9RTmamub0EC6b6hK4O gbBD9 FVxBVoS5hqCjAhfSVq21mnI8yTkUOaUltJI8 5YKZONECX1Nf4YR0pR44kEuG5fyXp 9mAcEJu/4U6hVkLmDG7rMKrvYqCFaczliVdUKO9rJesTllbGm/ox4nZJbOLXIYpk/Y0p/hnFcIYS BONgCrUqLxdeE/sq5Io z/tMoTZGWB7QR7CFWpcRGkTK2dtWgWLnz5a6O QLYfv3YH0ur3HC5/JDXodqgIXsQF90JeHRUuOkYtTDpbxfOJgxNb3itje5vTNZ/xbq/l8p7n/wyXr0ZFxh&_alc=1&_cb=1&dlink=http://directdownload80.com/o/.../Player-Chrome.exe

Remove player-chrome.exe - Powered by Reason Core Security