mediaplayerclassicinstaller.exe

The application mediaplayerclassicinstaller.exe has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from inst.greatfreesw.com.
MD5:
988fcfcd239f7fc01967603868b3abc1

SHA-1:
ffb5456b3899c324794714defc922a9cd1696c06

SHA-256:
27ec5b708cb82e6d44d2a6919d50f913fdb2781fcb88343b4eed437809c84d11

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 1:57:17 PM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Application.Bundler.OptimumInstaller.W
11.5.0.6191

Kaspersky
not-a-virus:AdWare.Win32.Verti
15.0.0.562

Reason Heuristics
Adware.Bundler (M)
16.6.16.18

File size:
238.6 KB (244,327 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\mediaplayerclassicinstaller.exe

File PE Metadata
Compilation timestamp:
12/4/2014 2:09:03 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:/P0cyd4eJ6IJGGIUmmB7xnqn1iJIg+apKceXXgr45oSF1:ud4e6IwGIm6H9apKceXXDoSF1

Entry address:
0x16D5E0

Entry point:
60, BE, 00, 40, 53, 00, 8D, BE, 00, D0, EC, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 55, B9, 16, 00, 57, 83, C3, 04, 53, 68, DE, 95, 03, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Entropy:
7.9871  (probably packed)

Code size:
236 KB (241,664 bytes)

The file mediaplayerclassicinstaller.exe has been seen being distributed by the following URL.

Remove mediaplayerclassicinstaller.exe - Powered by Reason Core Security