vlcmediaplayer-setup.exe

Download Admin

This is the Tightrope WebInstall which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application vlcmediaplayer-setup.exe by Download Admin has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the Tightrope WebInstall installer. The installer is marketed through download protals and search ads as the VideoLAN VLC media player but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Download Admin  (signed and verified)

MD5:
c566c5b09a3ad2c2ddde453b3dc99aed

SHA-1:
7cf9375c244806c262f2b109a45786d0398cbd5b

SHA-256:
ec8806a58e74345140ff9d97d783fd5b48f44bc558aaaaaaafc880a2426ee1d1

Scanner detections:
11 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
1/12/2025 11:04:47 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/DownloadAd.CK
8.3.1.6

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Adware.Downware.80
9.0.1.05190

ESET NOD32
Win32/DownloadAdmin.A.Gen potentially unwanted application
7.0.302.0

K7 AntiVirus
Unwanted-Program
13.204.16003

Malwarebytes
PUP.Optional.DownloadAdmin.C
v2015.05.22.09

NANO AntiVirus
Riskware.Nsis.Downware.dlgjls
0.30.24.1636

Reason Heuristics
PUP.Tightrope.Bundler
15.5.22.17

Sophos
PUA 'Download Admin'
5.14

SUPERAntiSpyware
Trojan.Agent/Gen-DownloadAdmin
9859

VIPRE Antivirus
Threat.4783369
40432

File size:
829.9 KB (849,808 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tightrope WebInstall

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\My documents\downloads\vlcmediaplayer-setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/2/2010 8:00:00 PM

Valid to:
5/29/2013 7:59:59 PM

Subject:
CN=Download Admin, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Download Admin, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
29529B0D185F8525A92A866D4A38DA3A

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:ndSNu2lc2/5kP2J4+sJ4sEL1jjs+THx3IIxa2al:nshx5k84+yDEL1jjtTH54Pl

Entry address:
0x3F6BD0

Entry point:
60, BE, 00, 20, 7F, 00, 8D, BE, 00, F0, C0, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.5361

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
20 KB (20,480 bytes)

The file vlcmediaplayer-setup.exe has been seen being distributed by the following URL.

Remove vlcmediaplayer-setup.exe - Powered by Reason Core Security