mediaplayerclassic.exe

Useful Software

This is part of the Verti bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file mediaplayerclassic.exe by Useful Software has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from inst.getswfree.net.
Publisher:
Useful Software  (signed and verified)

Version:
1.0.1.104

MD5:
a88626bca5938cf25c6df4a13ebe8b4a

SHA-1:
38e5f3220cd2251289146e0e4b4415ed356221a7

SHA-256:
51ab8cbcac0d8a8f6d8bcc1420c65fb38710b5a1705346679d6f66c19287588d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
1/12/2025 5:08:44 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Verti.UsefulSoftware (M)
15.12.6.8

File size:
360.8 KB (369,480 bytes)

Product version:
1.0.1.104

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\mediaplayerclassic.exe.t24wexu.partial

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/18/2014 7:00:00 PM

Valid to:
1/18/2016 6:59:59 PM

Subject:
CN=Useful Software, O=Useful Software, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
142135C80AA62D0F15501B4128FC6AEE

File PE Metadata
Compilation timestamp:
2/9/2015 1:03:41 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:3b2D9IIHOkbhVzS8DW4AqKa/62xioOWvj+xbWcs8LCmtYelapQPdciwo/U2Eq:3b2D9IIHXlsrc/5OxbWBuYiwOAo/U2Eq

Entry address:
0x16D5D0

Entry point:
60, BE, 00, B0, 51, 00, 8D, BE, 00, 60, EE, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8411

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
332 KB (339,968 bytes)

The file mediaplayerclassic.exe has been seen being distributed by the following URL.

Remove mediaplayerclassic.exe - Powered by Reason Core Security