uplayermediaplayer-setup.exe

Groovecom

The application uplayermediaplayer-setup.exe by Groovecom has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Remove uplayermediaplayer-setup.exe - Powered by Reason Core Security
Publisher:
Groovecom  (signed and verified)

MD5:
73e92d8a013a1a414699f81d844444c7

SHA-1:
f37cf272417b0a59cf848eb5f82a1615fc343d4a

SHA-256:
8a283646e5a4437c96e96f67f412c51955a67055d3c136a474e16d75890ce7d1

Scanner detections:
14 / 68

Status:
Adware

Analysis date:
12/6/2016 7:15:54 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.I
969

avast!
Malware-gen [Trj]
140608-0

Bitdefender
Application.Bundler.I
1.0.20.805

Dr.Web
Threat.Undefined
9.0.1.05190

ESET NOD32
Win32/DownloadAdmin.G potentially unwanted application
7.0.302.0

F-Secure
Application.Bundler.I
11.2014-10-06_3

G Data
Application.Bundler
14.6.24

MicroWorld eScan
Application.Bundler.I
15.0.0.483

NANO AntiVirus
Riskware.Win32.Downware.crgjbr
0.28.0.60253

Qihoo 360 Security
Win32/Application.468
1.0.0.1015

Reason Heuristics
PUP.Installer.Groovecom.Y
14.6.10.15

Sophos
Download Admin
4.98

VIPRE Antivirus
Threat.4783369
30086

Remove uplayermediaplayer-setup.exe - Powered by Reason Core Security
File size:
609.1 KB (623,704 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\uplayermediaplayer-setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/26/2014 3:30:00 AM

Valid to:
2/26/2017 3:29:59 AM

Subject:
CN=Groovecom, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Groovecom, L=SAN FRANCISCO, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0C8ED38817030CF19BE6EE39708627BA

File PE Metadata
Compilation timestamp:
6/22/2012 9:37:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:ErdiMybLCUVSG+u46LDu/eoABSafzNsZGwEL:E+bLcG+Ivu9ABrLWZpU

Entry address:
0x333B

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Entropy:
7.9692

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Remove uplayermediaplayer-setup.exe - Powered by Reason Core Security