vlc_setup.exe

VLC Media Player Installer

Savvy

The Adlogica setup manager, an installer that bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application vlc_setup.exe, “Deploy VLC Media Player along with various offers” by Savvy has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Adlogica Downloader installer. The installer is marketed through download protals and search ads as the VideoLAN VLC media player but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Savvy  (signed and verified)

Product:
VLC Media Player Installer

Description:
Deploy VLC Media Player along with various offers

Version:
2.0.4

MD5:
d0a1d22f510b71202af6d4aa0f91b843

SHA-1:
76fda8f7771eba7bd44fc05a5eb6906bd716d245

SHA-256:
9683a3cabf3f6b492de21d873184bb7f7435176fe9e5b13121111197c6f5455b

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
11/16/2024 4:28:53 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Adlogica (M)
17.1.26.10

File size:
1.2 MB (1,308,520 bytes)

Product version:
2.0.4

Copyright:
© downloadster.org

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adlogica Downloader

Language:
English (United States)

Common path:
C:\users\{user}\downloads\programs\vlc_setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/13/2013 5:30:00 AM

Valid to:
8/14/2014 5:29:59 AM

Subject:
CN=Savvy, O=Savvy, STREET=96 Jessie st, STREET=4th floor, L=SAN FRANCISCO, S=California, PostalCode=94105, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
397CE208945051D16EBC051D5ED4B1EC

File PE Metadata
Compilation timestamp:
7/20/2013 2:42:49 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x1053F0

Entry point:
55, 8B, EC, 83, C4, F0, B8, 14, 31, 50, 00, E8, E4, 21, F0, FF, 8B, 0D, 64, F5, 50, 00, 8B, 09, B2, 01, A1, DC, 2C, 4C, 00, E8, 28, 96, F5, FF, 8B, 15, 58, F6, 50, 00, 89, 02, A1, 64, F5, 50, 00, 8B, 00, E8, 2C, 2E, F6, FF, A1, 64, F5, 50, 00, 8B, 00, B2, 01, E8, C6, 4C, F6, FF, 8B, 0D, 4C, F3, 50, 00, A1, 64, F5, 50, 00, 8B, 00, 8B, 15, 48, 72, 4F, 00, E8, 1E, 2E, F6, FF, A1, 64, F5, 50, 00, 8B, 00, E8, 4A, 2F, F6, FF, E8, 39, FB, EF, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5141

Developed / compiled with:
Microsoft Visual C++

Code size:
1 MB (1,064,448 bytes)

Remove vlc_setup.exe - Powered by Reason Core Security