installation.exe

VID PLAY

The application installation.exe by VID PLAY has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from get.file16desktop.com.
Publisher:
VID PLAY  (signed and verified)

MD5:
ef02f567d9f67892833682961d38bea5

SHA-1:
b358b9f7c1e316374f8fdddccfa5b50846a74b7c

SHA-256:
df3b109dbf2465677b64fbf275439062352b8ce7812edab5b4190977bdcbc7c8

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
12/25/2024 7:40:03 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Outbrowse.Gen
7.11.199.126

ESET NOD32
Win32/OutBrowse.BQ potentially unwanted application
7.0.302.0

Kaspersky
not-a-virus:Downloader.NSIS.OutBrowse
15.0.0.543

Malwarebytes
PUP.Optional.OutBrowse
v2015.01.04.07

McAfee
Adware-OutBrowse.d
5600.6895

Reason Heuristics
PUP.Outborwse
15.2.5.12

Trend Micro House Call
Suspici.202D3B0F
7.2.4

VIPRE Antivirus
Threat.4657539
36340

File size:
580.9 KB (594,800 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
12/24/2014 4:27:48 AM

Valid to:
12/6/2015 1:32:26 AM

Subject:
CN=VID PLAY, O=VID PLAY, L=Dublin, C=IE

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11210F79EBB28F39FDDF0315ED2DCC340DE9

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:cXGt0y1kl86fssBFv4eqTHHjASyTotBP2mtL3LMdGRN0x:cWmy1klrssBFCj5TVLMS0

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9746

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installation.exe has been seen being distributed by the following URL.

Remove installation.exe - Powered by Reason Core Security