setup_vlc.exe

Secure Installer

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application setup_vlc.exe by Secure Installer has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. With this installer, users are expecting to download the VideoLAN VLC media player but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Secure Installer  (signed and verified)

MD5:
bb383d1c1b3e3d4899de443d9c903a60

SHA-1:
49ccb1a5fb510c13f155b6869515d98d3e6a7dcc

SHA-256:
f96a4110db542c5da5792089741a732a1eee095a736eaf67264e293e0207ef15

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/23/2024 7:08:26 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.121.78

Bkav FE
W32.HfsAutoA
1.3.0.4613

K7 AntiVirus
Unwanted-Program
13.174.10588

Reason Heuristics
PUP.Installer.SecureInstaller.J
14.2.20.20

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.131224

Sophos
Install Core
4.96

Vba32 AntiVirus
BScope.Malware-Cryptor.InstallCore.2691
3.12.24.3

VIPRE Antivirus
InstallCore
24608

File size:
1 MB (1,083,816 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\users\{user}\downloads\setup_vlc.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
9/25/2012 2:00:00 AM

Valid to:
9/26/2013 1:59:59 AM

Subject:
CN=Secure Installer, O=Secure Installer, STREET=720 Market Street, STREET=5th floor, L=San Francisco, S=CA, PostalCode=94102, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C3507C1ADDE6B4C52E5426990F85CA2B

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:GAkFhuUhrx64673IxuocwKj3DCgAh6KMEQgBKwV:GAyhuSd6NUxu3wKjGhY/s

Entry address:
0xCAA00

Entry point:
55, 8B, EC, 83, C4, F0, B8, 48, 29, 40, 00, E8, 05, EB, FF, FF, D6, 8B, C5, E8, 55, FF, FF, FF, 84, C0, 75, 04, 33, C0, 89, 06, 5A, 5D, 5F, 5E, 5B, C3, 8D, 40, 00, 53, 56, 57, 55, 83, C4, F8, 8B, D8, 8B, FB, 8B, 32, 8B, 43, 08, 3B, F0, 72, 6C, 8B, CE, 03, 4A, 04, 8B, E8, 03, 6B, 0C, 3B, CD, 77, 5E, 3B, F0, 75, 1B, 8B, 42, 04, 01, 43, 08, 8B, 42, 04, 29, 43, 0C, 83, 7B, 0C, 00, 75, 44, 8B, C3, E8, 35, FF, FF, FF, EB, 3B, 8B, 0A, 8B, 72, 04, 03, CE, 8B, F8, 03, 7B, 0C, 3B, CF, 75, 05, 29, 73, 0C, EB, 26, 8B...
 
[+]

Code size:
826 KB (845,824 bytes)

The file setup_vlc.exe has been seen being distributed by the following URL.

Remove setup_vlc.exe - Powered by Reason Core Security