video MediaPlay-Air

video MediaPlay-Air

Known Adware

by Robokid Technologies

What is video MediaPlay-Air?

video MediaPlay-Air is software application developed by Robokid Technologies. It is most commonly found on computers running Windows 7 with nearly 51.34% of installations running this operating system. video MediaPlay-Air's installer is typically 10.00 MB in size and installs around 206 files. The most common release is 1.34.7.1 with 84.84% of all installations currently using this version.

video MediaPlay-Air is most popular in the United States with 32.21% of installations residing in this country.

video MediaPlay-Air adds 6 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About video MediaPlay-Air?

Introducing MediaPlay-Air, a free browser extension developed by Freeven. This ad-supported software operates within the user's web browser environment as well as in the background. Typically bundled with third-party download managers, MediaPlay-Air may include potentially unwanted software offers to generate revenue through installations. Upon activation, MediaPlay-Air delivers various forms of advertisements to the browser, including banners, text hyperlinks, inline text ads, and transitional formats. It's important to note that these ads are not affiliated with or endorsed by the websites they appear on. In some instances, the software may inject banners into the header or footer of web pages or replace legitimate ads on the site. It's worth mentioning that some of the advertisements promoted by MediaPlay-Air may be considered malvertising, as they could potentially harm the user's PC. Additionally, uninstalling the program may not completely remove all of its contents, resulting in ads continuing to appear even after removal. Please note that the information presented is accurate as of the time of this publication and may be subject to change.

Multiple virus scanners have detected malware in video MediaPlay-Air.

260a4114-a81e-433b-82a6-cb34b98d71fb-4.exe (MD5: 8783f7a0c7740e7a7ae8f23849a5fd75) has been flagged by 26 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.16F
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.BAK
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Malwarebytes PUP.Optional.MediaPlayer.A
Panda Antivirus Trj/Genetic.gen
Symantec WS.Reputation.1
VIPRE Antivirus Crossrider (fs)
AhnLab-V3 PUP/Win32.CrossRider
Rising Antivirus PE:Malware.Obscure!1.9C59
McAfee Artemis!9F5D6B7D7025
McAfee-GW-Edition Artemis!9F5D6B7D7025
F-Prot W32/A-eb9ef301!Eldorado
Sophos AppRider
Fortinet FortiGate Riskware/Toolbar_CrossRider
Kingsoft AntiVirus Win32.Troj.NSIS.br.(kcloud)
NANO AntiVirus Riskware.Win32.AdLoad.dcabed
TrendMicro-HouseCall Suspicious_GEN.F47V0703
Bkav FE W32.CrossRiderN.Adware
Qihoo-360 HEUR/Malware.QVM10.Gen
Comodo Security ApplicUnwnt
Clam AntiVirus Win.Adware.Agent-7722
The Hacker Backdoor/VB.ipo
avast! Win32:Adware-gen [Adw]
260a4114-a81e-433b-82a6-cb34b98d71fb-11.exe (MD5: 9ca4d5abae3b02bfe27b85807e2569eb) has been flagged by 39 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.16F
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.BAK
Bitdefender Gen:Variant.Adware.Kazy.374062
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.27143
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
F-Secure Gen:Variant.Adware.Kazy.374062
G Data Gen:Variant.Adware.Kazy.374062
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Malwarebytes PUP.Optional.MediaPlayer.A
McAfee Artemis!9CA4D5ABAE3B
McAfee-GW-Edition Artemis!9CA4D5ABAE3B
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA KO
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V0731
VIPRE Antivirus Crossrider (fs)
AhnLab-V3 PUP/Win32.CrossRider
avast! Win32:Adware-gen [Adw]
Rising Antivirus PE:Malware.Obscure!1.9C59
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Qihoo-360 HEUR/Malware.QVM10.Gen
Fortinet FortiGate Riskware/Toolbar_CrossRider
nProtect Adware.Crossrider.AH
F-Prot W32/A-eb9ef301!Eldorado
K7 AntiVirus Trojan ( 0049bec01 )
K7GW Trojan ( 0049bec01 )
NANO AntiVirus Riskware.Win32.CrossRider.dcunoy
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
Vba32 AntiVirus AdWare.AdLoad
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.nr
Clam AntiVirus Win.Adware.Agent-7730
Bkav FE W32.CrossRiderN.Adware
The Hacker Backdoor/VB.ipo
24a744b3-dda3-4fde-85e8-e97ac1690f3f-5.exe (MD5: 9ae5432db1e517787a5310a5ea3af025) has been flagged by 17 scanners:
Scanner Software Result
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.bAH
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
Malwarebytes PUP.Optional.MediaPlayer.A
NANO AntiVirus Riskware.Win32.AdLoad.dbrdvm
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
VIPRE Antivirus Crossrider (fs)
Avira AntiVir Adware/CrossRider.A.18898
IKARUS anti.virus AdWare.Adload
avast! Win32:Adware-gen [Adw]
F-Prot W32/A-eb9ef301!Eldorado
Sophos AppRider
Qihoo-360 Win32/Virus.Adware.d6e
AVware Crossrider (fs)
Kingsoft AntiVirus Win32.Troj.NSIS.br.(kcloud)
TrendMicro-HouseCall Suspicious_GEN.F47V0705
24a744b3-dda3-4fde-85e8-e97ac1690f3f-4.exe (MD5: 6200c87a49417bbe83ec5231bedaaa8f) has been flagged by 36 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.A.16565
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.BAK
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
Malwarebytes PUP.Optional.MediaPlayer.A
McAfee Artemis!6200C87A4941
McAfee-GW-Edition Artemis!6200C87A4941
NANO AntiVirus Riskware.Win32.AdLoad.dcajcp
Panda Antivirus Trj/Genetic.gen
TrendMicro-HouseCall Suspicious_GEN.F47V0704
VIPRE Antivirus Crossrider (fs)
Qihoo-360 Win32/Virus.Adware.7ef
Symantec Trojan.ADH.2
IKARUS anti.virus AdWare.CrossRider
AhnLab-V3 PUP/Win32.CrossRider
Rising Antivirus PE:Malware.Obscure!1.9C59
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
G Data Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
F-Prot W32/A-eb9ef301!Eldorado
Sophos AppRider
AVware Crossrider (fs)
Kingsoft AntiVirus Win32.Troj.NSIS.br.(kcloud)
K7 AntiVirus Trojan ( 0049c2a41 )
K7GW Trojan ( 0049c2a41 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.px
Dr.Web Trojan.Crossrider.17413
avast! Win32:Adware-gen [Adw]
Bkav FE W32.CrossRiderN.Adware
Comodo Security ApplicUnwnt
Clam AntiVirus Win.Adware.Agent-7722
The Hacker Backdoor/VB.ipo
24a744b3-dda3-4fde-85e8-e97ac1690f3f-2.exe (MD5: 94d4f5166de317b212184e2521cd13a7) has been flagged by 37 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.A.16586
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.bAJ
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/A-eb9ef301!Eldorado
K7 AntiVirus Trojan ( 0049bf0b1 )
K7GW Trojan ( 0049bf0b1 )
Malwarebytes PUP.Optional.MediaPlayer.A
McAfee Artemis!94D4F5166DE3
McAfee-GW-Edition Artemis!94D4F5166DE3
NANO AntiVirus Riskware.Win32.AdLoad.dcabxp
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
TrendMicro-HouseCall Suspicious_GEN.F47V0704
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374109
AhnLab-V3 PUP/Win32.CrossRider
Bitdefender Gen:Variant.Adware.Kazy.374109
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374109 (B)
F-Secure Gen:Variant.Adware.Kazy.374109
G Data Gen:Variant.Adware.Kazy.374109
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Kingsoft AntiVirus Win32.Troj.NSIS.br.(kcloud)
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
VIPRE Antivirus Crossrider (fs)
AVware Crossrider (fs)
Comodo Security ApplicUnwnt
Symantec Trojan.ADH.2
Qihoo-360 Win32/Virus.Adware.7b1
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
avast! Win32:Adware-gen [Adw]
Dr.Web Trojan.Crossrider.17413
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.px
Bkav FE W32.CrossRiderN.Adware
Clam AntiVirus Win.Adware.Agent-7722
The Hacker Backdoor/VB.ipo

Software Behaviors

Scheduled tasks:
  • a879d4bc-778f-4de6-aa9c-da091e1221bd-2.exe is scheduled as a task named 'temp_a879d4bc-778f-4de6-aa9c-da091e1221bd-2'.
  • video MediaPlay-Air-codedownloader.exe is scheduled as a task named '06f50292-fe67-4afb-a25c-1b7efccb0b93-1'.
  • 95e41e79-34c1-4521-bf9c-07600f8fd004-2.exe is scheduled as a task named 'temp_95e41e79-34c1-4521-bf9c-07600f8fd004-2'.
  • d18df992-be7e-4a46-a500-1ebd2c15b05e-2.exe is scheduled as a task named 'temp_d18df992-be7e-4a46-a500-1ebd2c15b05e-2'.
  • video MediaPlay-Air-nova.exe is scheduled as a task named 'temp_64276799-ff5d-4abd-a3a9-cbb3fe4eb3a7-7'.
  • 64276799-ff5d-4abd-a3a9-cbb3fe4eb3a7-2.exe is scheduled as a task named 'temp_64276799-ff5d-4abd-a3a9-cbb3fe4eb3a7-2'.

Startup Entries

Startup tasks:
  • video MediaPlay-Air-nova.exe is automatically launched at startup through a scheduled task named 0a6f1111-2a6e-43ed-8874-5e226f5e743b-7.
  • video MediaPlay-Air-codedownloader.exe is automatically launched at startup through a scheduled task named 06f50292-fe67-4afb-a25c-1b7efccb0b93-1.
  • fa4b397d-de55-4578-a7a9-4aa500149b9b-5.exe is automatically launched at startup through a scheduled task named fa4b397d-de55-4578-a7a9-4aa500149b9b-5_user.
  • fa4b397d-de55-4578-a7a9-4aa500149b9b-4.exe is automatically launched at startup through a scheduled task named fa4b397d-de55-4578-a7a9-4aa500149b9b-4.
  • fa4b397d-de55-4578-a7a9-4aa500149b9b-11.exe is automatically launched at startup through a scheduled task named fa4b397d-de55-4578-a7a9-4aa500149b9b-3.
  • b2fd8ca8-3aaf-48c2-8ca1-f694f3a9625d-11.exe is automatically launched at startup through a scheduled task named b2fd8ca8-3aaf-48c2-8ca1-f694f3a9625d-3.

Software Details

URL:
https://crossrider.com/install/59599-video-mediaplayer
Support:
–
Installation path:
C:\Program Files\video mediaplay-air
Uninstaller:
C:\Program Files\video MediaPlay-Air\Uninstall.exe /fcp=1
Size:
10.00 MB
Language:
English

video MediaPlay-Air Executable Details

Primary executable:
utils.exe
Name:
video MediaPlay-Air
Path:
C:\Program Files\video mediaplay-air\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by video MediaPlay-Air
File Type Filename MD5
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
EXE
a0bdc8051a740904d9e5f24d697f6875
EXE
8783f7a0c7740e7a7ae8f23849a5fd75
EXE
9ca4d5abae3b02bfe27b85807e2569eb
EXE
9ae5432db1e517787a5310a5ea3af025
EXE
6200c87a49417bbe83ec5231bedaaa8f
EXE
94d4f5166de317b212184e2521cd13a7
EXE
bcb8f1aaa5f3d4cf227d9dda33f6d757
EXE
17269b8fa1b9599479b1d154147a7551
EXE
b4bf095ac072c0e53a106280f0375426