realplayer.exe

RealNetworks Installer (32-bit)

RealNetworks, Inc.

This is installed with RealPlayer Cloud. The file has been seen being downloaded from director.real.com and multiple other hosts.
Publisher:
RealNetworks, Inc.  (signed and verified)

Product:
RealNetworks Installer (32-bit)

Description:
RealNetworks Installer

Version:
4.7.0.40

MD5:
a42f6f1b1644972c76831f36fae58ac5

SHA-1:
1ffd8a1c328eaf485c34748b319bd47767955e5c

SHA-256:
5c34c46da268e98aebdeacd8c0d1599e65b6d39e6a442de041ad57d56e06d82e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 10:28:11 AM UTC  (today)

File size:
755.2 KB (773,296 bytes)

Product version:
4.7.0.40

Original file name:
rnsetup.EXE

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
Thawte, Inc.

Valid from:
8/3/2011 8:00:00 AM

Valid to:
8/16/2013 7:59:59 AM

Subject:
CN="RealNetworks, Inc.", OU=MS&S, O="RealNetworks, Inc.", L=Seattle, S=Washington, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
17FDFBD161CDD4A95804A4808D678FCA

File PE Metadata
Compilation timestamp:
4/5/2013 3:31:07 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:sO4iuVvBAX6+ImEubiHSyfemZ5ObvEqQbpUqKGMG8CLPXTRQOyLA3EHLwzWhs0oo:AvBAX2DubMGmZ5Ob6saZMLHOWhDo+4S1

Entry address:
0x3287

Entry point:
E8, F2, 3F, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 58, 27, 41, 00, 00, 75, 18, E8, D9, 39, 00, 00, 6A, 1E, E8, 23, 38, 00, 00, 68, FF, 00, 00, 00, E8, 33, 35, 00, 00, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40, 50, 6A, 00, FF, 35, 58, 27, 41, 00, FF, 15, FC, D0, 40, 00, 8B, F8, 85, FF, 75, 26, 6A, 0C, 5E, 39, 05, C4, 2E, 41, 00, 74, 0D, 53, E8, 06, 1D, 00, 00, 59, 85, C0, 75, A9, EB, 07, E8, 32, 03, 00, 00, 89, 30, E8, 2B, 03, 00, 00, 89...
 
[+]

Entropy:
6.6185

Code size:
48 KB (49,152 bytes)

The file realplayer.exe has been discovered within the following program.

RealPlayer Cloud  by RealNetworks, Inc.
Publisher's description - “RealPlayer Cloud enables you to move, watch and share your videos. When you share videos with friends and family they’ll be able to play them on any device or operating system, without downloading the RealPlayer Cloud app.”
www.real.com
6% remove it
 
Powered by Should I Remove It?

The file realplayer.exe has been seen being distributed by the following 31 URLs.

http://director.real.com/realplayer?type=rpsp_us&rppr=search2&pcode=srchrv&cpath=ppcse&rsrc=msn_us_rp_search_branded_realplayer_only_x1Exact_Match&s_kwcid=TC|1028566|real player||S|e|18781190536&gclid=CMS_oL6o7rcCFa9eQgodN1YAcw

http://director.real.com/realplayer?type=rpsp_us&rppr=search2&pcode=srchrv&cpath=ppcse&rsrc=msn_us_rp_search_branded_realplayer_only_x1Exact_Match&s_kwcid=TC|1028566|real player||S|e|18781190536&gclid=COneiY2u6bcCFQSZ4AodW1wAfQ

http://director.real.com/realplayer?type=rpsp_us&rppr=search2&pcode=srchrv&cpath=ppcse&rsrc=msn_us_rp_search_RP_-_Brand_x1RealPlayer_-_Only_-_Exact

http://director.real.com/realplayer?type=rpsp_us&rppr=search2&pcode=srchrv&cpath=ppcse&rsrc=msn_us_rp_search_branded_realplayer_only_x1Exact_Match&s_kwcid=TC|1028566|real player||S|e|18781190656&gclid=CP3gxMaM8bYCFQgx4AodhzIAcw

http://director.real.com/realplayer?type=rpsp_us&rppr=search2&pcode=srchrv&cpath=ppcse&rsrc=msn_us_rp_search_RP_-_Brand_x1Latest_-_Broad

Latest 30 of 31 download URLs

Scan realplayer.exe - Powered by Reason Core Security