« on: May 23, 2016, 05:07 PM »
instead of installing any malware I took another approach with AHK.
running multiple VLC sessions then tiling the windows with
PostMessage, 0x111, 405, 0,, ahk_class Shell_TrayWnd
mostly does what I was looking for. There are better player than VLC,
but VLC has some good switches and the playlist feature is quite nice too.  :-*

you may simply try another ad-blocker. I use uBlock Origin for instance.
(in another browser though  :D )

« on: April 20, 2016, 03:34 PM »
cheers 4wd :Thmbsup:

malware analysis report

« on: April 19, 2016, 04:45 PM »
4wd, you are right, it works after enabling internet in the VM.

as you mentioned it connects to (an IP address that is part of the CloudFlare)
and also (a Google IP address).

maybe someone with Wireshark knowledge wants to have a look at, what's happening here exactly ?
for myself, I am not sure about this software, I'll probably revert to a backup before installation...  :-\

« on: April 18, 2016, 04:10 PM »
thanks skwire, I was not aware of the software.
great user interface, and it does what I was looking for. :Thmbsup:

I did some additional tests, it seems to be coded in .NET (c#).
Apparently it's not working in a VM, probably due to the GPU acceleration it's using.
The program is compressed/obfuscated, why would anyone pack a free app?
Also I was not able to find a portable version.
Seems clean according to Virustotal, though I am not sure...  :huh:

Edit: someone in comments at VT claims this is malware:
Deepviz analysis

result: #malware
accuracy: 100.0%
8 matched behavioural rules:
Gathers system data
Suspicious delay
Manipulates Internet Explorer settings
More info at

