Home Malware Programs Potentially Unwanted Programs (PUPs) SysPlayer

SysPlayer

Posted: July 21, 2015

Threat Metric

Threat Level: 1/10
Infected PCs: 1,091
First Seen: July 21, 2015
Last Seen: April 18, 2023
OS(es) Affected: Windows

Despite the fact that SysPlayer is promoted as a helpful and lightweight media player, the experts unanimously define it as a Potentially Unwanted Program (PUP). There are several reasons why the majority of PC users don't appreciate this tool. First of all, it often receives the permission for installation in a rather confusing way. The developer of SysPlayer, which is created by the company named Goobzo, sometimes relies on the help of third-party applications for the spreading of their media player. This process is known as "bundling", and has extensive use when it comes to software with questionable utility. If the user doesn't read the details, he may load SysPlayer unwillingly. The users who find themselves on the official product page of this application, which can be found at sysplayer.com, may be tricked to download it by the advertising slogans. When it enters, however, the PUP immediately inserts numerous ads in Google Chrome, Mozilla Firefox and Internet Explorer. This behavior often leaves the clients annoyed as the generated pop-ups, banners and in-text ads tend to be rather intrusive. Their appearance may even lead to a drop in the functionality. In addition, the promoted platforms are often very questionable, and may even be dangerous. SysPlayer doesn't offer anything more than the other free media players, so you should seriously consider deleting it in case the ads bother you.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\sysplayer\sysplayer.exe File name: C:\Program Files\sysplayer\sysplayer.exe
MD5: f90605a70adf5e235839c9fb95a0f512
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
libvlc.dll File name: libvlc.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
libvlccore.dll File name: libvlccore.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
QtCore4.dll File name: QtCore4.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
QtGui4.dll File name: QtGui4.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
QtNetwork4.dll File name: QtNetwork4.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
QtSql4.dll File name: QtSql4.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
QtWebKit4.dll File name: QtWebKit4.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
QtXml4.dll File name: QtXml4.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
SPRemove.exe File name: SPRemove.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

CLSID{F6607505-0E5B-47E6-809E-EAEE53F1E4D7}File name without pathSysPlayer.lnkRegexp file mask%WINDIR%\System32\Tasks\SysPlayerUpdHKEY..\..\..\..{RegistryKeys}Software\Classes\*\ShellEx\ContextMenuHandlers\SysPlayerMenuExtSOFTWARE\Classes\Directory\shell\sysplayer.enqueueSOFTWARE\Clients\Media\SysPlayerSOFTWARE\Clients\Media\SysPlayer\Caps\FileAssociationsSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SysPlayerUpdSOFTWARE\RegisteredApplications\SysPlayerSoftware\SysPlayerSOFTWARE\Wow6432Node\Clients\Media\SysPlayerSOFTWARE\Wow6432Node\Clients\Media\SysPlayer\Caps\FileAssociationsSOFTWARE\Wow6432Node\RegisteredApplications\SysPlayerSOFTWARE\Wow6432Node\SysPlayerHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SysPlayer

Additional Information

The following directories were created:
%PROGRAMFILES%\SysPlayer%PROGRAMFILES(x86)%\SysPlayer
Loading...