setup_adobe_shockwave_player.exe

Adobe Shockwave Player

Install Helper

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup_adobe_shockwave_player.exe by Install Helper has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The installer is marketed through download protals and search ads as Adobe Shockwave Player but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Install Helper  (signed and verified)

Product:
Adobe Shockwave Player

Version:
3.0.0.105

MD5:
e3dc65137603e63c07b06e50568b1592

SHA-1:
fa511d99b6612e05c1e8a401b587f4a4b9bfcae1

SHA-256:
080715b47172158f7f31848b729b4bf88c8f7dbca9b00755deff33b66f87a246

Scanner detections:
21 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
1/13/2025 12:49:49 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.AirInstaller.5
5777167

AhnLab V3 Security
PUP/Win32.Bundler
2015.06.15

Avira AntiVirus
TR/Crypt.XPACK.Gen
8.3.1.6

Arcabit
Trojan.Application.Bundler.AirInstaller.5
1.0.0.425

AVG
Generic
2016.0.3078

Bitdefender
Gen:Variant.Application.Bundler.AirInstaller.5
1.0.20.830

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.DownloadAssistant.S
22457

Dr.Web
Trojan.Vittalia.76
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.AirInstaller
10.0.0.5366

ESET NOD32
Win32/DownloadAssistant.A potentially unwanted application
7.0.302.0

F-Secure
Riskware.Gen:Variant.Application.Bundler
5.14.151

G Data
Gen:Variant.Application.Bundler.AirInstaller
15.6.25

K7 AntiVirus
Unwanted-Program
13.205.16242

MicroWorld eScan
Gen:Variant.Application.Bundler.AirInstaller.5
16.0.0.498

NANO AntiVirus
Trojan.Win32.Vittalia.dqfrig
0.30.24.2086

Norman
Gen:Variant.Application.Bundler.AirInstaller.5
02.06.2015 14:23:46

Panda Antivirus
Trj/Genetic.gen
15.06.15.09

Reason Heuristics
PUP.Vittalia.Bundler
15.6.15.9

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.15613

VIPRE Antivirus
Threat.4782985
40830

File size:
961.6 KB (984,704 bytes)

Product version:
3.0.0.105

Copyright:
(c) Install Helper

Original file name:
setup_adobe_shockwave_player.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup_adobe_shockwave_player.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
5/19/2015 5:00:00 PM

Valid to:
5/19/2016 4:59:59 PM

Subject:
CN=Install Helper, O=Install Helper, L=Vancouver, S=British Columbia, C=CA

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
0575634D1B3373331074EB7C4751AB12

File PE Metadata
Compilation timestamp:
6/15/2015 1:36:25 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:PkRY/Zpqq7qeLt9/SqeCqUMA9arWok8F6uR+e:8RuoKUqeEai+Fh+e

Entry address:
0x126A

Entry point:
55, 8B, EC, 83, EC, 10, 53, 56, 57, 6A, 00, FF, 15, 08, 10, 49, 00, 8B, F8, 33, D2, 8B, CF, 8B, 5F, 3C, 03, DF, 2B, 05, 1C, 10, 40, 00, 89, 45, F4, 1B, D2, F7, D8, 89, 55, F8, 0F, B7, 73, 14, 83, D2, 00, F7, DA, 89, 75, F0, 52, 8B, 93, A0, 00, 00, 00, 50, 8B, 44, 1E, 24, 03, 05, 28, 10, 40, 00, 50, FF, B3, A4, 00, 00, 00, E8, 88, FD, FF, FF, 8B, 54, 1E, 28, 83, C4, 10, A1, 28, 10, 40, 00, 2B, D0, 83, FA, 01, 76, 0D, 8B, 4C, 1E, 24, 03, C8, 03, CF, E8, F2, FE, FF, FF, A1, 20, 10, 40, 00, 83, C6, 40, 03, F3...
 
[+]

Entropy:
7.0513

Developed / compiled with:
Microsoft Visual C++

Code size:
574.5 KB (588,288 bytes)

The file setup_adobe_shockwave_player.exe has been seen being distributed by the following URL.

Remove setup_adobe_shockwave_player.exe - Powered by Reason Core Security