AtlasPlayer.exe

AtlasPlayer

ITVA

The application AtlasPlayer.exe by ITVA has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
iTVA LLC  (signed by ITVA)

Product:
AtlasPlayer

Description:
Atlas Player

Version:
3.3.2.0

MD5:
637e6bb48ccfcb3ecae1e960515f0cbd

SHA-1:
74ff37ee2ea52693ffeed8022d1509f73ca93e0c

SHA-256:
4ecc57ec2fbf63184b3a1a3e196df5b1f926f7bc98f0a0e77f9941aa75e99546

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/26/2024 11:34:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.iTVA (M)
16.9.20.17

File size:
10.6 MB (11,119,248 bytes)

Product version:
3.3.2.0

Copyright:
iTVA LLC

Trademarks:
iTVA, atlasplayer.ru, atlasplayer.com

Original file name:
AtlasPlayer.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\atlas player\atlasplayer.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/26/2014 4:00:00 AM

Valid to:
9/27/2015 3:59:59 AM

Subject:
CN=ITVA, O=ITVA, STREET="27/2 Liter A Pom 6-N, prospekt Parkhomenko", L=Saint-Petersburg, S=RU, PostalCode=194356, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
303B020D4BEC85F9AC725DFC5A02D1E8

File PE Metadata
Compilation timestamp:
10/13/2014 5:18:17 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:0M7Rz0OAlFgmpGkd76aYVEZU+bSvX8nUpIntOmUNbJAFgkNi1wCgnAWfWv:0gzllkd7xUkSX8nUinoLlAFgkNi1wZna

Entry address:
0x8708E4

Entry point:
55, 8B, EC, 83, C4, E8, 53, 33, C0, 89, 45, EC, 89, 45, E8, B8, E8, 19, C6, 00, E8, C3, E0, 79, FF, 33, C0, 55, 68, 5A, 0A, C7, 00, 64, FF, 30, 64, 89, 20, B2, 01, A1, 54, DD, C6, 00, E8, 95, 6E, 79, FF, 8B, D8, B8, F8, A5, C9, 00, 8B, D3, 85, D2, 74, 03, 83, EA, F8, E8, FC, C9, 79, FF, 8D, 55, E8, 33, C0, E8, 46, 61, 79, FF, 8B, 45, E8, 8D, 55, EC, E8, 3F, 74, 7B, FF, 8D, 45, EC, BA, 74, 0A, C7, 00, E8, 7A, 9D, 79, FF, 8B, 45, EC, B2, 01, E8, BC, 6E, 7B, FF, 84, C0, 0F, 84, C9, 00, 00, 00, E8, C7, 6D, F5...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
8.4 MB (8,846,336 bytes)

Remove AtlasPlayer.exe - Powered by Reason Core Security