vlc-installer.exe

Boot Compute

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application vlc-installer.exe, “Software Installer ” by Boot Compute has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. With this installer, users are expecting to download the VideoLAN VLC media player but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Software Installer   (signed by Boot Compute)

Product:
Software Installer

Description:
Software Installer

Version:
2.4.8.1

MD5:
6d00509d96e018494ef06c880eb93d02

SHA-1:
54e3656f7c2803a7de6b548dccd8485fa3112d81

SHA-256:
9a25ddcd399e8f48f091f829148495e4601878f9d97a0ec31f129dd2aaec80ea

Scanner detections:
21 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/14/2024 3:16:41 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
2015.03.25

avast!
Win32:PUP-gen [PUP]
150320-0

AVG
Adware AdPlugin.ABP
2014.0.4311

Comodo Security
Application.Win32.AgentCV.HWYE
21526

Dr.Web
Adware.iBryte.478
9.0.1.05190

ESET NOD32
Win32/AdWare.iBryte.BD application
7.0.302.0

F-Prot
W32/A-4ab0b861
v6.4.7.1.166

G Data
Win32.Adware.IBryte
15.3.25

herdProtect (fuzzy)
2015.6.30.9

IKARUS anti.virus
Trojan.Win32.Badur
t3scan.1.8.6.0

K7 AntiVirus
Adware
13.202.15367

Kaspersky
not-a-virus:Downloader.Win32.Agent
15.0.0.543

NANO AntiVirus
Trojan.Win32.Badur.dejghk
0.30.8.659

nProtect
Trojan-Clicker/W32.iBryte.248184
15.03.24.01

Quick Heal
TrojanDownloader.Badur.A5
3.15.14.00

Reason Heuristics
PUP.Bundler.Adknowledge
15.3.25.14

Vba32 AntiVirus
3.12.26.3

VIPRE Antivirus
Threat.4798837
38552

Zillya! Antivirus
Downloader.Agent.Win32.208408
2.0.0.2114

File size:
242.4 KB (248,184 bytes)

Product version:
2.4.8.1

Copyright:
Copyright (C) 2013 Software Installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
English (United States)

Common path:
C:\users\{user}\downloads\vlc-installer.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/23/2014 7:00:00 PM

Valid to:
3/24/2015 6:59:59 PM

Subject:
CN=Boot Compute, O=Boot Compute, STREET="4600 Madison Ave, 10th FL", L=Kansas City, S=Missouri, PostalCode=64112, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
059AEF62ABD7F83178378663E98BDE5C

File PE Metadata
Compilation timestamp:
8/27/2014 4:00:17 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:LashrGNpqMdElO6amEDke4HJViL/z37Fj7N1B39wGslsHr:LashrGrldEWTDkbJqL3J7HgGsOr

Entry address:
0x11263

Entry point:
E8, BA, 05, 00, 00, E9, D7, FC, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 18, 72, 41, 00, 89, 0D, 14, 72, 41, 00, 89, 15, 10, 72, 41, 00, 89, 1D, 0C, 72, 41, 00, 89, 35, 08, 72, 41, 00, 89, 3D, 04, 72, 41, 00, 66, 8C, 15, 30, 72, 41, 00, 66, 8C, 0D, 24, 72, 41, 00, 66, 8C, 1D, 00, 72, 41, 00, 66, 8C, 05, FC, 71, 41, 00, 66, 8C, 25, F8, 71, 41, 00, 66, 8C, 2D, F4, 71, 41, 00, 9C, 8F, 05, 28, 72, 41, 00, 8B, 45, 00, A3, 1C, 72, 41, 00, 8B, 45, 04, A3, 20, 72, 41, 00, 8D, 45, 08, A3, 2C, 72, 41...
 
[+]

Entropy:
7.2060

Code size:
70 KB (71,680 bytes)

The file vlc-installer.exe has been seen being distributed by the following URL.

Remove vlc-installer.exe - Powered by Reason Core Security