fastoplayersetup.exe

The application fastoplayersetup.exe has been detected as a potentially unwanted program by 26 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from osdsoft.com.
MD5:
1718623ee35fc75557722945971ccf73

SHA-1:
1e46fdca4594a698a91c0ecd7a06223a33f9a11a

SHA-256:
2dd436a08499d72b63c42749fd49cc977bbd63c8a6deece4d702d9694f151966

Scanner detections:
26 / 68

Status:
Potentially unwanted

Analysis date:
2/25/2025 1:05:08 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Kazy.723691
297

Agnitum Outpost
Trojan.DR.Agent
7.1.1

Avira AntiVirus
TR/Agent.925184.9
8.3.2.2

Arcabit
Trojan.Adware.Kazy.DB0AEB
1.0.0.567

avast!
Win32:Adware-gen [Adw]
2014.9-160413

AVG
Generic6
2017.0.2775

Bitdefender
Gen:Variant.Adware.Kazy.723691
1.0.20.520

Comodo Security
Application.Win32.OxyPumper.~G
23304

Dr.Web
Trojan.DownLoader16.23258
9.0.1.0104

Emsisoft Anti-Malware
Gen:Variant.Adware.Kazy.723691
8.16.04.13.07

ESET NOD32
Win32/Adware.OxyPumper (variant)
10.12296

Fortinet FortiGate
W32/Agent.BJPOGP!tr
4/13/2016

G Data
Gen:Variant.Adware.Kazy.723691
16.4.25

IKARUS anti.virus
Trojan-Dropper.Win32.Agent
t3scan.1.9.5.0

K7 AntiVirus
Riskware
13.210.17342

Kaspersky
Trojan-Dropper.Win32.Agent.bjpogp
14.0.0.368

McAfee
RDN/Generic Dropper
5600.6431

MicroWorld eScan
Gen:Variant.Adware.Kazy.723691
17.0.0.312

NANO AntiVirus
Trojan.Win32.Agent.dxgqvp
0.30.26.3725

Panda Antivirus
Trj/Genetic.gen
16.04.13.07

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Adware.Generic.AT (M)
16.4.13.7

Rising Antivirus
PE:Malware.RDM.06!5.C[F1]
23.00.65.16411

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R0EBC0PIJ15
10.465.13

VIPRE Antivirus
Trojan.Win32.Generic
44072

File size:
903.5 KB (925,184 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\fastoplayersetup.exe

File PE Metadata
Compilation timestamp:
9/11/2015 4:45:44 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:gMWlyTZmMnemjLVwOTqdiQ9fzrqNJPrEkfKlET95AzJQ3auYjZlnznfjHzNGRZzb:gMtZvjLSle5AzKauY11adhB3Bu9

Entry address:
0x7CE5A

Entry point:
E9, D1, BF, 04, 00, E9, 9C, 1D, 01, 00, E9, 97, 43, 06, 00, E9, 22, 40, 03, 00, E9, 1D, 10, 04, 00, E9, 78, 40, 03, 00, E9, A3, 6A, 01, 00, E9, AE, DC, 06, 00, E9, D1, 09, 04, 00, E9, 74, B7, 06, 00, E9, CF, 1E, 04, 00, E9, AA, A0, 02, 00, E9, 35, 06, 01, 00, E9, 70, A2, 09, 00, E9, 7B, 1B, 09, 00, E9, E6, 0E, 07, 00, E9, 51, 8E, 04, 00, E9, 7C, FE, 05, 00, E9, 47, 22, 04, 00, E9, 92, A0, 09, 00, E9, 3D, 87, 05, 00, E9, 5A, 9D, 04, 00, E9, E3, 05, 03, 00, E9, BE, 85, 03, 00, E9, 79, 13, 05, 00, E9, 54, CF...
 
[+]

Developed / compiled with:
Microsoft Visual C++ 8.0 (Debug)

The file fastoplayersetup.exe has been seen being distributed by the following URL.

Remove fastoplayersetup.exe - Powered by Reason Core Security