uplayermediaplayer-setup.exe

Groovecom

The application uplayermediaplayer-setup.exe by Groovecom has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from files4.safelink9.com and multiple other hosts.
Publisher:
Groovecom  (signed and verified)

MD5:
e3dcff281c515f3e319afeac00e336a0

SHA-1:
e29352f6c6ef235c6f38b0d7dfcf7aeff2aec722

SHA-256:
ba80545d0c6c1d6a18af242adf04fb7cd14da02a4f281411847b0761f94638ea

Scanner detections:
14 / 68

Status:
Adware

Analysis date:
12/25/2024 12:21:00 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.I
968

Bitdefender
Application.Bundler.I
1.0.20.815

Dr.Web
Adware.Downware.2220
9.0.1.0163

ESET NOD32
Win32/DownloadAdmin
8.9876

F-Secure
Application.Bundler.I
11.2014-12-06_5

G Data
Application.Bundler
14.6.24

K7 AntiVirus
Trojan
13.178.12257

MicroWorld eScan
Application.Bundler.I
15.0.0.489

NANO AntiVirus
Riskware.Win32.Downware.crgjbr
0.28.0.59921

Qihoo 360 Security
Win32/Application.468
1.0.0.1015

Reason Heuristics
PUP.Installer.Groovecom.Y
14.6.12.9

Sophos
Download Admin
4.98

Trend Micro House Call
TROJ_GEN.F47V0525
7.2.163

VIPRE Antivirus
DownloadAdmin
29818

File size:
609.1 KB (623,696 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\uplayermediaplayer-setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/26/2014 1:00:00 AM

Valid to:
2/26/2017 12:59:59 AM

Subject:
CN=Groovecom, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Groovecom, L=SAN FRANCISCO, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0C8ED38817030CF19BE6EE39708627BA

File PE Metadata
Compilation timestamp:
6/22/2012 8:07:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:8rdiMybLCUVSG+u46LDu/eoABSafzNsZGwEL:8+bLcG+Ivu9ABrLWZpU

Entry address:
0x333B

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file uplayermediaplayer-setup.exe has been seen being distributed by the following 4 URLs.

Remove uplayermediaplayer-setup.exe - Powered by Reason Core Security