playerplusx.exe

The application playerplusx.exe has been detected as a potentially unwanted program by 32 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from www.playerplus.com.
MD5:
6153b9d3c6315f06ed398eba3c18df7a

SHA-1:
85a979f3316192652f4d25eb56d23e8003cc8068

SHA-256:
a2eeab551ae60c62576495136ececcd5601fb09f2fd6d3480c6da570fd7f703f

Scanner detections:
32 / 68

Status:
Potentially unwanted

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
5/10/2024 2:55:09 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Boxore
7.1.1

AhnLab V3 Security
Win-Adware/Relevant.25264286
14.08.14

avast!
Win32:PUP-gen [PUP]
2014.9-140814

Comodo Security
UnclassifiedMalware
16091

Dr.Web
Adware.Boxore.1
9.0.1.0226

Emsisoft Anti-Malware
Riskware.Win32.Toolbar.Babylon.AMN
8.14.10.29.10

ESET NOD32
Win32/Adware.Boxore (variant)
8.8274

K7 AntiVirus
Adware
13.176.11595

Malwarebytes
Adware.Boxore
v2014.08.14.09

McAfee
Artemis!6153B9D3C631
5600.7039

NANO AntiVirus
Riskware.Win32.SwiftCleaner.jgngy
0.28.0.58720

Norman
Suspicious_Gen4.YGSM
11.20140814

Panda Antivirus
Generic Malware
14.08.14.09

Qihoo 360 Security
Win32/Trojan.Downloader.53c
1.0.0.1015

Rising Antivirus
PE:Trojan.Win32.Generic.1313BB63!320060259
23.00.65.14812

Trend Micro House Call
TROJ_GE.A5CB2F1A
7.2.226

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

VIPRE Antivirus
Babylon
17254

XVirus List
Win32.Detected
2.8.14

File size:
24.1 MB (25,264,286 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\playerplusx.exe

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:TOZ7nKiovkWcoNFfSu960biBju9E5HXK8/IKqH1c39gHSD38ZEJFrJK0xe0i51bh:TOMLFP960Yjz0KqVc+ylJFrJRxe0ah

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file playerplusx.exe has been seen being distributed by the following URL.

Remove playerplusx.exe - Powered by Reason Core Security