video MediaPlay-Air

video MediaPlay-Air

Known Adware

by Robokid Technologies

What is video MediaPlay-Air?

video MediaPlay-Air is software application developed by Robokid Technologies. It is most commonly found on computers running Windows 7 with nearly 51.34% of installations running this operating system. video MediaPlay-Air's installer is typically 10.00 MB in size and installs around 206 files. The most common release is 1.34.7.1 with 84.84% of all installations currently using this version.

video MediaPlay-Air is most popular in the United States with 32.21% of installations residing in this country.

video MediaPlay-Air adds 6 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About video MediaPlay-Air?

Introducing MediaPlay-Air, a free browser extension developed by Freeven. This ad-supported software operates within the user's web browser environment as well as in the background. Typically bundled with third-party download managers, MediaPlay-Air may include potentially unwanted software offers to generate revenue through installations. Upon activation, MediaPlay-Air delivers various forms of advertisements to the browser, including banners, text hyperlinks, inline text ads, and transitional formats. It's important to note that these ads are not affiliated with or endorsed by the websites they appear on. In some instances, the software may inject banners into the header or footer of web pages or replace legitimate ads on the site. It's worth mentioning that some of the advertisements promoted by MediaPlay-Air may be considered malvertising, as they could potentially harm the user's PC. Additionally, uninstalling the program may not completely remove all of its contents, resulting in ads continuing to appear even after removal. Please note that the information presented is accurate as of the time of this publication and may be subject to change.

Multiple virus scanners have detected malware in video MediaPlay-Air.

260a4114-a81e-433b-82a6-cb34b98d71fb-4.exe (MD5: 8783f7a0c7740e7a7ae8f23849a5fd75) has been flagged by 26 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.16F
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.BAK
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Malwarebytes PUP.Optional.MediaPlayer.A
Panda Antivirus Trj/Genetic.gen
Symantec WS.Reputation.1
VIPRE Antivirus Crossrider (fs)
AhnLab-V3 PUP/Win32.CrossRider
Rising Antivirus PE:Malware.Obscure!1.9C59
McAfee Artemis!9F5D6B7D7025
McAfee-GW-Edition Artemis!9F5D6B7D7025
F-Prot W32/A-eb9ef301!Eldorado
Sophos AppRider
Fortinet FortiGate Riskware/Toolbar_CrossRider
Kingsoft AntiVirus Win32.Troj.NSIS.br.(kcloud)
NANO AntiVirus Riskware.Win32.AdLoad.dcabed
TrendMicro-HouseCall Suspicious_GEN.F47V0703
Bkav FE W32.CrossRiderN.Adware
Qihoo-360 HEUR/Malware.QVM10.Gen
Comodo Security ApplicUnwnt
Clam AntiVirus Win.Adware.Agent-7722
The Hacker Backdoor/VB.ipo
avast! Win32:Adware-gen [Adw]
260a4114-a81e-433b-82a6-cb34b98d71fb-11.exe (MD5: 9ca4d5abae3b02bfe27b85807e2569eb) has been flagged by 39 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.16F
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.BAK
Bitdefender Gen:Variant.Adware.Kazy.374062
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.27143
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
F-Secure Gen:Variant.Adware.Kazy.374062
G Data Gen:Variant.Adware.Kazy.374062
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Malwarebytes PUP.Optional.MediaPlayer.A
McAfee Artemis!9CA4D5ABAE3B
McAfee-GW-Edition Artemis!9CA4D5ABAE3B
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA KO
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V0731
VIPRE Antivirus Crossrider (fs)
AhnLab-V3 PUP/Win32.CrossRider
avast! Win32:Adware-gen [Adw]
Rising Antivirus PE:Malware.Obscure!1.9C59
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Qihoo-360 HEUR/Malware.QVM10.Gen
Fortinet FortiGate Riskware/Toolbar_CrossRider
nProtect Adware.Crossrider.AH
F-Prot W32/A-eb9ef301!Eldorado
K7 AntiVirus Trojan ( 0049bec01 )
K7GW Trojan ( 0049bec01 )
NANO AntiVirus Riskware.Win32.CrossRider.dcunoy
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
Vba32 AntiVirus AdWare.AdLoad
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.nr
Clam AntiVirus Win.Adware.Agent-7730
Bkav FE W32.CrossRiderN.Adware
The Hacker Backdoor/VB.ipo
24a744b3-dda3-4fde-85e8-e97ac1690f3f-5.exe (MD5: 9ae5432db1e517787a5310a5ea3af025) has been flagged by 17 scanners:
Scanner Software Result
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.bAH
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
Malwarebytes PUP.Optional.MediaPlayer.A
NANO AntiVirus Riskware.Win32.AdLoad.dbrdvm
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
VIPRE Antivirus Crossrider (fs)
Avira AntiVir Adware/CrossRider.A.18898
IKARUS anti.virus AdWare.Adload
avast! Win32:Adware-gen [Adw]
F-Prot W32/A-eb9ef301!Eldorado
Sophos AppRider
Qihoo-360 Win32/Virus.Adware.d6e
AVware Crossrider (fs)
Kingsoft AntiVirus Win32.Troj.NSIS.br.(kcloud)
TrendMicro-HouseCall Suspicious_GEN.F47V0705
24a744b3-dda3-4fde-85e8-e97ac1690f3f-4.exe (MD5: 6200c87a49417bbe83ec5231bedaaa8f) has been flagged by 36 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.A.16565
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.BAK
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
Malwarebytes PUP.Optional.MediaPlayer.A
McAfee Artemis!6200C87A4941
McAfee-GW-Edition Artemis!6200C87A4941
NANO AntiVirus Riskware.Win32.AdLoad.dcajcp
Panda Antivirus Trj/Genetic.gen
TrendMicro-HouseCall Suspicious_GEN.F47V0704
VIPRE Antivirus Crossrider (fs)
Qihoo-360 Win32/Virus.Adware.7ef
Symantec Trojan.ADH.2
IKARUS anti.virus AdWare.CrossRider
AhnLab-V3 PUP/Win32.CrossRider
Rising Antivirus PE:Malware.Obscure!1.9C59
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
G Data Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
F-Prot W32/A-eb9ef301!Eldorado
Sophos AppRider
AVware Crossrider (fs)
Kingsoft AntiVirus Win32.Troj.NSIS.br.(kcloud)
K7 AntiVirus Trojan ( 0049c2a41 )
K7GW Trojan ( 0049c2a41 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.px
Dr.Web Trojan.Crossrider.17413
avast! Win32:Adware-gen [Adw]
Bkav FE W32.CrossRiderN.Adware
Comodo Security ApplicUnwnt
Clam AntiVirus Win.Adware.Agent-7722
The Hacker Backdoor/VB.ipo
24a744b3-dda3-4fde-85e8-e97ac1690f3f-2.exe (MD5: 94d4f5166de317b212184e2521cd13a7) has been flagged by 37 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.A.16586
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.bAJ
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/A-eb9ef301!Eldorado
K7 AntiVirus Trojan ( 0049bf0b1 )
K7GW Trojan ( 0049bf0b1 )
Malwarebytes PUP.Optional.MediaPlayer.A
McAfee Artemis!94D4F5166DE3
McAfee-GW-Edition Artemis!94D4F5166DE3
NANO AntiVirus Riskware.Win32.AdLoad.dcabxp
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
TrendMicro-HouseCall Suspicious_GEN.F47V0704
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374109
AhnLab-V3 PUP/Win32.CrossRider
Bitdefender Gen:Variant.Adware.Kazy.374109
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374109 (B)
F-Secure Gen:Variant.Adware.Kazy.374109
G Data Gen:Variant.Adware.Kazy.374109
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Kingsoft AntiVirus Win32.Troj.NSIS.br.(kcloud)
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
VIPRE Antivirus Crossrider (fs)
AVware Crossrider (fs)
Comodo Security ApplicUnwnt
Symantec Trojan.ADH.2
Qihoo-360 Win32/Virus.Adware.7b1
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
avast! Win32:Adware-gen [Adw]
Dr.Web Trojan.Crossrider.17413
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.px
Bkav FE W32.CrossRiderN.Adware
Clam AntiVirus Win.Adware.Agent-7722
The Hacker Backdoor/VB.ipo

Software Behaviors

Scheduled tasks:
  • a879d4bc-778f-4de6-aa9c-da091e1221bd-2.exe is scheduled as a task named 'temp_a879d4bc-778f-4de6-aa9c-da091e1221bd-2'.
  • video MediaPlay-Air-codedownloader.exe is scheduled as a task named '06f50292-fe67-4afb-a25c-1b7efccb0b93-1'.
  • 95e41e79-34c1-4521-bf9c-07600f8fd004-2.exe is scheduled as a task named 'temp_95e41e79-34c1-4521-bf9c-07600f8fd004-2'.
  • d18df992-be7e-4a46-a500-1ebd2c15b05e-2.exe is scheduled as a task named 'temp_d18df992-be7e-4a46-a500-1ebd2c15b05e-2'.
  • video MediaPlay-Air-nova.exe is scheduled as a task named 'temp_64276799-ff5d-4abd-a3a9-cbb3fe4eb3a7-7'.
  • 64276799-ff5d-4abd-a3a9-cbb3fe4eb3a7-2.exe is scheduled as a task named 'temp_64276799-ff5d-4abd-a3a9-cbb3fe4eb3a7-2'.

Startup Entries

Startup tasks:
  • video MediaPlay-Air-nova.exe is automatically launched at startup through a scheduled task named 0a6f1111-2a6e-43ed-8874-5e226f5e743b-7.
  • video MediaPlay-Air-codedownloader.exe is automatically launched at startup through a scheduled task named 06f50292-fe67-4afb-a25c-1b7efccb0b93-1.
  • fa4b397d-de55-4578-a7a9-4aa500149b9b-5.exe is automatically launched at startup through a scheduled task named fa4b397d-de55-4578-a7a9-4aa500149b9b-5_user.
  • fa4b397d-de55-4578-a7a9-4aa500149b9b-4.exe is automatically launched at startup through a scheduled task named fa4b397d-de55-4578-a7a9-4aa500149b9b-4.
  • fa4b397d-de55-4578-a7a9-4aa500149b9b-11.exe is automatically launched at startup through a scheduled task named fa4b397d-de55-4578-a7a9-4aa500149b9b-3.
  • b2fd8ca8-3aaf-48c2-8ca1-f694f3a9625d-11.exe is automatically launched at startup through a scheduled task named b2fd8ca8-3aaf-48c2-8ca1-f694f3a9625d-3.

Software Details

URL:
https://crossrider.com/install/59599-video-mediaplayer
Support:
–
Installation path:
C:\Program Files\video mediaplay-air
Uninstaller:
C:\Program Files\video MediaPlay-Air\Uninstall.exe /fcp=1
Size:
10.00 MB
Language:
English

video MediaPlay-Air Executable Details

Primary executable:
utils.exe
Name:
video MediaPlay-Air
Path:
C:\Program Files\video mediaplay-air\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by video MediaPlay-Air
File Type Filename MD5
EXE
673813416e225a13a4c237ac9f00f957
EXE
7b08d470cd797796ce54f59bb3e362c6
EXE
3b6e47b9e6c970530aa76889903ff98c
EXE
f4db8400baa7275031ff48c1f46bfb09
EXE
e09dc2879cc4f9cca326557a19c2aa32
EXE
69b31a840a6c5db2f8c753f6a9848483
EXE
d50fc8d49e69e07bdbfbcedda01ba3f2
EXE
bab64a4cd0508acaffa65d58f9fd4a57
EXE
80d9b70c7e29f976e080a57204ca8cb8
EXE
ea91ca3fa91c08c470fc7fc518933002