vlcmediaplayer-setup.exe

Tomorrow Software Installer

Spiral Media

The application vlcmediaplayer-setup.exe, “Tomorrow Software Installer ” by Spiral Media has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Tomorrow Software Installer installer. With this installer, users are expecting to download the VideoLAN VLC media player but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware. It is also typically executed from an Internet Explorer cache folder.
Publisher:
Tomorrow Software  (signed by Spiral Media)

Product:
Tomorrow Software Installer

Description:
Tomorrow Software Installer

Version:
2.0.0.1

MD5:
5415287c262021ffad139f524727f160

SHA-1:
fe94563c5aeb8cb336c2ca499208b87d47411ee7

SHA-256:
f796f79e5fcca0d8f2d4241243ae27398ebe7223c9dac9dc62a9d8d61d75dc52

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/30/2024 10:09:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.TomorrowSoftware (M)
17.2.8.7

File size:
877.4 KB (898,456 bytes)

Product version:
2.0.0.1

Copyright:
Copyright (C) 2015

Original file name:
tomorrow-setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tomorrow Software Installer

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\vlcmediaplayer-setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/23/2015 8:00:00 PM

Valid to:
6/23/2016 7:59:59 PM

Subject:
CN=Spiral Media, O=Spiral Media, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6D229836E7034F48BD411B17636E7FEF

File PE Metadata
Compilation timestamp:
6/26/2015 9:54:21 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0xC7A2

Entry point:
E8, 3C, 05, 00, 00, E9, 57, FD, FF, FF, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 58, 4B, 41, 00, 89, 0D, 54, 4B, 41, 00, 89, 15, 50, 4B, 41, 00, 89, 1D, 4C, 4B, 41, 00, 89, 35, 48, 4B, 41, 00, 89, 3D, 44, 4B, 41, 00, 66, 8C, 15, 70, 4B, 41, 00, 66, 8C, 0D, 64, 4B, 41, 00, 66, 8C, 1D, 40, 4B, 41, 00, 66, 8C, 05, 3C...
 
[+]

Entropy:
7.9553  (probably packed)

Code size:
51.5 KB (52,736 bytes)

Remove vlcmediaplayer-setup.exe - Powered by Reason Core Security