vplayer.12.934.9704.exe

vpl

The application vplayer.12.934.9704.exe, “vpl Setup ” has been detected as a potentially unwanted program by 12 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. The file has been seen being downloaded from www.dropbox.com.
Product:
vpl

Description:
vpl Setup

MD5:
2fd4a83aac9d0f8d05a157660cf9f07c

SHA-1:
bd83f2f3645e0f9dff6d16e261c6ff149ad9892a

SHA-256:
a86628467142dd566cb524451cfa9955f040113fc5a33a635e604ea8c1627dba

Scanner detections:
12 / 68

Status:
Potentially unwanted

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Analysis date:
12/24/2024 3:02:48 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.BundleInstaller
2016.03.30

Avira AntiVirus
ADWARE/Browse.941205.1
8.3.3.4

avast!
Win32:Adware-gen [Adw]
2014.9-160808

ESET NOD32
Win32/Adware.BrowSecX (variant)
10.13261

IKARUS anti.virus
PUA.KeyLogger.Activitymonitor
t3scan.2.0.9.0

K7 AntiVirus
Adware
13.220.19174

Kaspersky
Trojan-Dropper.Win32.Dapato
14.0.0.-219

NANO AntiVirus
Trojan.Win32.Dapato.eaxlma
1.0.18.7201

Panda Antivirus
Generic Suspicious
16.08.08.06

Qihoo 360 Security
HEUR/QVM06.1.0000.Malware.Gen
1.0.0.1120

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16806

VIPRE Antivirus
Trojan.Win32.Generic
48270

File size:
919.1 KB (941,205 bytes)

Product version:
2.0

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\vplayer.12.934.9704.exe

File PE Metadata
Compilation timestamp:
1/15/2016 11:22:50 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:CxGKL4XDV0TRrvstlM+HtHZyyaBVLj9o6k1vh/BZS0hUX:n64zcqT5y9/fmDJo

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 34, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 1E, D8, FF, FF, E8, 6D, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 33, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 54, 86...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file vplayer.12.934.9704.exe has been seen being distributed by the following URL.

Remove vplayer.12.934.9704.exe - Powered by Reason Core Security