mediaplayerclassic.exe

The application mediaplayerclassic.exe has been detected as a potentially unwanted program by 19 anti-malware scanners. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from inst.great-free-apps.net and multiple other hosts.
MD5:
c63eb06f0f554da4d27922008f69b5aa

SHA-1:
c17dcea11f95b25f2e44bc727347b46d79390e77

SHA-256:
a365b573a9f013ed6d6f76fbbc37ec596cfb7e9b37fdc63b8b6137e98f4fd769

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 12:02:02 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.G
865

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
TR/Trash.Gen
7.11.30.172

AVG
Usefus
2015.0.3343

Bitdefender
Application.Bundler.G
1.0.20.1325

Dr.Web
Adware.Downware.2712
9.0.1.0265

ESET NOD32
Win32/Verti (variant)
8.9756

Fortinet FortiGate
Riskware/Verti
9/22/2014

F-Secure
Application.Bundler.G
11.2014-22-09_2

G Data
Application.Bundler
14.9.24

herdProtect (fuzzy)
2014.12.5.0

McAfee
Artemis!136AC13E7FC6
5600.6926

MicroWorld eScan
Application.Bundler.G
15.0.0.795

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.22.18

Sophos
Verti
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10343

Trend Micro House Call
TROJ_GEN.F47V0425
7.2.265

VIPRE Antivirus
Rocketfuel Installer
28876

XVirus List
Win.Detected
2.3.31

File size:
367.5 KB (376,288 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\mediaplayerclassic.exe

File PE Metadata
Compilation timestamp:
2/21/2014 1:09:13 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:J4+MixC0NSs6FHtHwotSUOF5bGiExOEO71TgSAOr5LqE1cxfro7zF1W+LVy5p6ah:JF+0cNt/MUOFQ5xYaSV5LqE1cxfro7zC

Entry address:
0x226E1

Entry point:
E8, 7E, A7, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 90, 10, 45, 00, 33, C5, 89, 45, FC, 83, 7D, 08, FF, 57, 74, 09, FF, 75, 08, E8, 09, 86, 00, 00, 59, 83, A5, E0, FC, FF, FF, 00, 6A, 4C, 8D, 85, E4, FC, FF, FF, 6A, 00, 50, E8, EB, B3, FF, FF, 8D, 85, E0, FC, FF, FF, 89, 85, D8, FC, FF, FF, 8D, 85, 30, FD, FF, FF, 83, C4, 0C, 89, 85, DC, FC, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC...
 
[+]

Entropy:
6.3845

Code size:
220 KB (225,280 bytes)

The file mediaplayerclassic.exe has been seen being distributed by the following 4 URLs.

http://inst.great-free-apps.net/dl/42/1703/5552/.../

Remove mediaplayerclassic.exe - Powered by Reason Core Security