vlc-installer.exe

Boot Compute

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application vlc-installer.exe, “Software Installer ” by Boot Compute has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. The installer is marketed through download protals and search ads as the VideoLAN VLC media player but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Software Installer   (signed by Boot Compute)

Product:
Software Installer

Description:
Software Installer

Version:
2.4.8.1

MD5:
e369c562ec941703dbb9a3a8738f6651

SHA-1:
5672ee6de22b9b84aaf01a784933876f02e5c779

SHA-256:
fa1b4f4ce9801377d5937d5c359d24f4621240a0fa926ce1dc10430152107fce

Scanner detections:
19 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/14/2024 2:54:03 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
2015.03.25

avast!
Win32:PUP-gen [PUP]
2014.9-160120

AVG
Adware AdPlugin
2017.0.2858

Comodo Security
Application.Win32.AgentCV.HWYE
21526

Dr.Web
Adware.iBryte.478
9.0.1.020

ESET NOD32
Win32/AdWare.iBryte.BD application
10.7.0.302.0

F-Prot
W32/A-4ab0b861
v6.4.7.1.166

G Data
Win32.Adware.IBryte
16.1.25

IKARUS anti.virus
Trojan.Win32.Badur
t3scan.1.8.6.0

K7 AntiVirus
Adware
13.202.15367

Kaspersky
not-a-virus:Downloader.Win32.Agent
14.0.0.787

NANO AntiVirus
Trojan.Win32.Badur.dejghk
0.30.8.659

nProtect
Trojan-Clicker/W32.iBryte.248184
15.03.24.01

Quick Heal
TrojanDownloader.Badur.A5
1.16.14.00

Reason Heuristics
PUP.Adknowledge.BootCompute.Bundler (M)
16.1.20.12

Vba32 AntiVirus
3.12.26.3

VIPRE Antivirus
Threat.4798837
38552

Zillya! Antivirus
Downloader.Agent.Win32.208408
2.0.0.2114

File size:
238.9 KB (244,600 bytes)

Product version:
2.4.8.1

Copyright:
Copyright (C) 2013 Software Installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
English (United States)

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/23/2014 6:00:00 PM

Valid to:
3/24/2015 5:59:59 PM

Subject:
CN=Boot Compute, O=Boot Compute, STREET="4600 Madison Ave, 10th FL", L=Kansas City, S=Missouri, PostalCode=64112, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
059AEF62ABD7F83178378663E98BDE5C

File PE Metadata
Compilation timestamp:
8/30/2014 3:00:23 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:DqDfl1wCY4Oa2mEDke4HJViL/z37Fj7N1B39wGslpw8:+Dl6BNTDkbJqL3J7HgGss8

Entry address:
0x10513

Entry point:
E8, BA, 05, 00, 00, E9, D7, FC, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 18, 62, 41, 00, 89, 0D, 14, 62, 41, 00, 89, 15, 10, 62, 41, 00, 89, 1D, 0C, 62, 41, 00, 89, 35, 08, 62, 41, 00, 89, 3D, 04, 62, 41, 00, 66, 8C, 15, 30, 62, 41, 00, 66, 8C, 0D, 24, 62, 41, 00, 66, 8C, 1D, 00, 62, 41, 00, 66, 8C, 05, FC, 61, 41, 00, 66, 8C, 25, F8, 61, 41, 00, 66, 8C, 2D, F4, 61, 41, 00, 9C, 8F, 05, 28, 62, 41, 00, 8B, 45, 00, A3, 1C, 62, 41, 00, 8B, 45, 04, A3, 20, 62, 41, 00, 8D, 45, 08, A3, 2C, 62, 41...
 
[+]

Entropy:
7.2189

Code size:
66.5 KB (68,096 bytes)

The file vlc-installer.exe has been seen being distributed by the following URL.

Remove vlc-installer.exe - Powered by Reason Core Security