vlc_setup.exe

Premium Installer

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application vlc_setup.exe by Premium Installer has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. With this installer, users are expecting to download the VideoLAN VLC media player but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
ExpressInstaller  (signed by Premium Installer)

Product:
ExpressInstaller

Version:
3, 7, 1, 0

MD5:
5e2d2c9ca9966a19670cc9ecc219c8f7

SHA-1:
6b5bd911cedfcf15436ee4e1983472719776f6f6

SHA-256:
2f05d006669821380f9a794c3301a11c681bbff112cc97c1dbe5451c4f434b2f

Scanner detections:
12 / 68

Status:
Adware

Explanation:
This setup/installer bundles various adware components.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 2:05:14 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Installer-K [PUP]
2014.9-160215

AVG
Adware AdInstaller.ExpressInstall
2017.0.2833

Dr.Web
Trojan.DownLoader11.3480
9.0.1.046

ESET NOD32
Win32/AdWare.iBryte.K.gen application
10.7.0.302.0

F-Prot
W32/Ibryte.G.gen
v6.4.6.5.141

K7 AntiVirus
Trojan
13.191.14631

Kaspersky
not-a-virus:AdWare.Win32.iBryte
14.0.0.658

Malwarebytes
PUP.Optional.iBryte
v2016.02.15.07

Reason Heuristics
PUP.Adknowledge.PremiumInstaller.Installer (M)
16.2.15.7

Sophos
PUA 'iBryte Optimum Installer'
59

VIPRE Antivirus
Threat.4778314
36468

Zillya! Antivirus
Trojan.Buzus.Win32.118759
2.0.0.2034

File size:
1.6 MB (1,714,840 bytes)

Product version:
3, 7, 1, 0

Copyright:
Copyright (C) 2013 ExpressInstaller

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
English (United States)

Common path:
C:\users\{user}\downloads\vlc_setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/13/2013 5:30:00 AM

Valid to:
8/3/2014 5:29:59 AM

Subject:
CN=Premium Installer, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Premium Installer, L=Wilmington, S=Delaware, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
35BB74B905C01CE61DA131BA49337F33

File PE Metadata
Compilation timestamp:
9/19/2013 1:36:05 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:BBEicqUW8F1dK5w4NzAbxFcqUW8AmcqeT7nW8mcqUW8J/h8e:sTW8FL32AFIW8+nW8vW8hj

Entry address:
0x414C

Entry point:
E8, FB, 35, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 5C, C2, 41, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 44, C0, 41, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63...
 
[+]

Entropy:
7.0298

Code size:
105 KB (107,520 bytes)

Remove vlc_setup.exe - Powered by Reason Core Security