player-chrome.exe

Monarch Downloads

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application player-chrome.exe, “Fusion Install ” by Monarch Downloads has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Adknowledge Fusion installer. The installer is marketed through download protals and search ads as Google's Chrome web browser but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Fusion Install   (signed by Monarch Downloads)

Product:
Fusion Install

Description:
Fusion Install

Version:
2.4.8.1

MD5:
0a69ecb661fd9cf9911017647c0857b3

SHA-1:
69db5b053a3b9efd1cbc9660af8bb92fd68ca031

SHA-256:
0708e6552c7a7a2f13fe9d12d8a678970248f16e8a27f407b9e366b93d849b68

Scanner detections:
1 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/28/2024 11:23:33 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Adknowledge (M)
17.3.9.2

File size:
145.4 KB (148,864 bytes)

Product version:
2.4.8.1

Copyright:
Copyright (C) Fusion Install

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
English (United States)

Common path:
C:\users\{user}\downloads\player-chrome.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/24/2014 12:00:00 AM

Valid to:
3/24/2015 11:59:59 PM

Subject:
CN=Monarch Downloads, O=Monarch Downloads, STREET="4600 Madison Ave, 10th FL", L=Kansas City, S=Missouri, PostalCode=64112, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6ED4FE307D4F8068EFCDF769A3803C67

File PE Metadata
Compilation timestamp:
8/19/2014 7:34:44 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x5D6D

Entry point:
E8, 46, 05, 00, 00, E9, 36, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 08, A2, 40, 00, 89, 0D, 04, A2, 40, 00, 89, 15, 00, A2, 40, 00, 89, 1D, FC, A1, 40, 00, 89, 35, F8, A1, 40, 00, 89, 3D, F4, A1, 40, 00, 66, 8C, 15, 20, A2, 40, 00, 66, 8C, 0D, 14, A2, 40, 00, 66, 8C, 1D, F0, A1, 40, 00, 66, 8C, 05, EC, A1, 40, 00, 66, 8C, 25, E8, A1, 40, 00, 66, 8C, 2D, E4, A1, 40, 00, 9C, 8F, 05, 18, A2, 40, 00, 8B, 45, 00, A3, 0C, A2, 40, 00, 8B, 45, 04, A3, 10, A2, 40, 00, 8D, 45, 08, A3, 1C, A2, 40...
 
[+]

Code size:
23 KB (23,552 bytes)

The file player-chrome.exe has been seen being distributed by the following URL.

http://download1251bucket.com/track/install?gluid=gyaEYiQh4MLIikqJpf02aAjEj91 Xfm Ks72lRfk6rfuPl6AT8hCX6ESaS/BuNlmjuo82 G6I/52mPL/OiszHEOOEA0Ue2J6imDbMXq5g/WKrSgDss5CieMYsbE/sR pkTVqFSUsquO0VHFeiYR bfyvcZAYj07ahtAgiGac2lmJVdI/aTUwgSsMyYFLy4E/J17H/VShgXoAH3BwZJRxcUqZ0Noa6/6a&_alc=1&_cb=1&dlink=http://easysetupinstall.com/o/.../Player-Chrome.exe

Remove player-chrome.exe - Powered by Reason Core Security