Anyone know what this is: Media_Player_Setup.exe / Win32.iBryte

Do you have a question? Post it now! No Registration Necessary.  Now with pictures!

These URL's came in a spam today:



I replaced some alpha-numeric junk with "fuckoff" in the second link.

One of those URL's spawned a bunch of stuff that resulted in a diversion
to here:


Which is some sort of fake adobe download page.  The Install link
resulted in this:


I replaced some alpha-junk in the above URL with "blabla"  

Although this will work:



File version:
Description: Fusion Install
Copyright 2013 Fusion Install
226,168 bytes

VT scan:

Detection ratio:  11 / 54

VT had apparently not seen this sample before.

AVG             Generic_s.BZ
Antiy-AVL       Riskware[:not-a-virus]/Win32.iBryte.jgi
CMC             Packed.Win32.TDSS.2!O
ESET-NOD32      a variant of Win32/AdWare.iBryte.AL
K7AntiVirus     Unwanted-Program ( 0040f84f1 )
K7GW            Unwanted-Program ( 0040f84f1 )
Kaspersky       not-a-virus:AdWare.Win32.iBryte.jgi
Kingsoft        Win32.Troj.iBryte.j.(kcloud)
Malwarebytes    PUP.Optional.OptimumInstaller.A
Panda           Trj/Genetic.gen
Sophos          iBryte Optimum Installer

iBryte Optimum Installer is an installer which bundles legitimate
applications with offers for additional third party applications that
may be unwanted by the user. Such third party applications are typically
installed onto users’ computers by default, but may include an option to
‘opt-out’ during or after the installation process.

Site Timeline