softonicuninstallwebplayer.exe

Kreapixel

The application softonicuninstallwebplayer.exe, “Webplayer uninstall” by Kreapixel has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. This file is typically installed with the program Webplayer by Kreapixel which is a potentially unwanted software program. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from softs.illyx.com.
Publisher:
Kreapixel  (signed and verified)

Description:
Webplayer uninstall

Version:
1.0.0.0

MD5:
68302182e805c89cc7163599619b13bf

SHA-1:
32917baf51851535a5cf95b88b03ce7f39391bdb

SHA-256:
bf15b66e4a4762af1433a244aca614e5bbf33e3288bacf3c1f2ff24feddd2f04

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/23/2024 4:23:57 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Kreapixel.Installer (M)
16.2.1.22

File size:
442.7 KB (453,320 bytes)

Copyright:
Kreapixel inc.

File type:
Executable application (Win32 EXE)

Language:
French (France)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\softonicuninstallwebplayer.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
4/28/2013 2:00:00 AM

Valid to:
4/29/2014 1:59:59 AM

Subject:
CN=Kreapixel, OU=24, O=Kreapixel, L=Bergerac, S=Dordogne, C=FR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
73E829C616F33571512B97CC95565619

File PE Metadata
Compilation timestamp:
1/29/2012 10:32:28 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:IuIlWqB+ihabs7Ch9KwyF5LeLodp2D1Mmakda0qLeOAtkBfLxb7b9Pjd:z6Wq4aaE6KwyF5L0Y2D1PqLM+Lxbj

Entry address:
0xDBEB0

Entry point:
60, BE, 00, A0, 49, 00, 8D, BE, 00, 70, F6, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
268 KB (274,432 bytes)

The file softonicuninstallwebplayer.exe has been discovered within the following program.

Webplayer  by Kreapixel
Webplayer is an adware program that integrates into the user's web browsers (IE, Chrome, Firefox) and will perform a number of functions mostly designed to generate advertising supported or affiliate revenue.
About 62% of users remove it
 
Powered by Should I Remove It?

The file softonicuninstallwebplayer.exe has been seen being distributed by the following URL.

Remove softonicuninstallwebplayer.exe - Powered by Reason Core Security