installer_mediaplayer_spanish.exe

Gec

The application installer_mediaplayer_spanish.exe has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a setup program which is used to install the application. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.appsstockgift.com.
Product:
Gec

Version:
2.8

MD5:
a57ba6e616ece8310aad5b473a859555

SHA-1:
b41cd122624ec83337080acdcb2178d2f474446f

SHA-256:
fb5339324d1c0a3befb95d0ac4fb0a14b6670a6ce3307196e55f66868a4e3a41

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
1/7/2025 8:29:23 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Adware InstallCore.BKI
2015.0.4604

ESET NOD32
Win32/InstallCore.ADC potentially unwanted application
8.0.319.0

Reason Heuristics
Adware.Bundler.ET (M)
16.7.25.22

File size:
1.2 MB (1,270,272 bytes)

Product version:
2.8

Original file name:
ClickOnceSetup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\installer_mediaplayer_spanish.exe

File PE Metadata
Compilation timestamp:
2/18/2016 7:49:06 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:ZmSglSwRkwGlt8DB9l00NeC8dlPCrykfjiDnj00++IU764zosi:ZXMXR98tC9Bod5a54zos

Entry address:
0x12F0AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.2 MB (1,233,408 bytes)

The file installer_mediaplayer_spanish.exe has been seen being distributed by the following URL.

Remove installer_mediaplayer_spanish.exe - Powered by Reason Core Security