vlcmediaplayer-setup.exe

Power Play Media

The application vlcmediaplayer-setup.exe by Power Play Media has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Tomorrow Software Installer installer. With this installer, users are expecting to download the VideoLAN VLC media player but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
FYI Fun Installer Setup  (signed by Power Play Media)

Product:
FYI Fun Installer Setup

Version:
3.9.3.6729

MD5:
cc4714bb4a85ddf126b4815edec93e35

SHA-1:
ec7b206df179f032f8edc32969addf991022b9f8

SHA-256:
963cbc1aec895a8464be6a5d1f6a191cb7c141abe908ac3ae780233ed03106f9

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 6:01:33 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.TomorrowSoftware (M)
17.2.9.18

File size:
870.8 KB (891,720 bytes)

Product version:
3.9.3.6729

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tomorrow Software Installer

Language:
English (United States)

Common path:
C:\users\{user}\downloads\vlcmediaplayer-setup.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
10/14/2015 1:17:38 AM

Valid to:
10/14/2016 1:17:38 AM

Subject:
CN=Power Play Media, O=Power Play Media, L=San Francisco, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
42E6D7782DB3A869

File PE Metadata
Compilation timestamp:
10/3/2014 5:37:33 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x262B

Entry point:
E8, E0, B2, 00, 00, E9, E2, AB, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 81, EC, 1C, 02, 00, 00, 53, 55, 8B, AC, 24, 28, 02, 00, 00, 56, 57, 6A, 01, 55, C7, 44, 24, 24, 00, 00, 00, 00, E8, 3F, 3C, 00, 00, D9, 7C, 24, 1A, 0F, B7, 44, 24, 1A, 0D, 00, 0C, 00, 00, 89, 44, 24, 1C, 8D, 44, 24, 24, 50, D9, 6C, 24, 20, 6A, 00, 6A, 02, 55, DF, 7C, 24, 2C, 8B, 74, 24, 2C, D9, 6C, 24, 2A, E8, 1E, 3B, 00, 00, 8B, 4C, 24, 34, 8B, F8, 83, C4, 18, 8D, 1C, 0F, 89, 5C, 24, 14, 85, FF, 75, 11, 55, E8, 14, 3B, 00...
 
[+]

Code size:
52.5 KB (53,760 bytes)

Remove vlcmediaplayer-setup.exe - Powered by Reason Core Security