dosukoi.exe

Alexey Kurilenko

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application dosukoi.exe by Alexey Kurilenko has been detected as adware by 17 anti-malware scanners. It uses Web-Pick's InstalleRex download manager and installer to bundle potentially unwanted ad-supported software which includes toolbars and browser extensions through a pay-per-install monetization scheme.
Publisher:
Alexey Kurilenko  (signed and verified)

MD5:
bb57fc5359eeb9e8235f1acfe15e87ff

SHA-1:
2345bd95b32bbfb7435bcfdafca1bec00416409d

SHA-256:
7cce6bd43d09271c4052bfb1094c84feee573abf33d2655c28e60ed92a0ab494

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Uses the InstalleRex from WebPick Internet Holdings to install bundled add-ons including toolbars and other web browser extensions.

Analysis date:
5/9/2024 4:29:58 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.MultiPlug
7.1.1

Avira AntiVirus
Adware/MultiPlug.aob
7.11.166.208

avast!
Win32:InstalleRex-CH [PUP]
2014.9-140812

AVG
Adware Generic5
2015.0.3385

Comodo Security
Application.Win32.GreenApp.RR
19188

Dr.Web
Trojan.Crossrider.28215
9.0.1.0226

ESET NOD32
Win32/AdWare.MultiPlug.BF (variant)
8.10242

IKARUS anti.virus
AdWare.SaveNet
t3scan.1.6.1.0

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
14.0.0.3405

Malwarebytes
PUP.Optional.DownloaderSS
v2014.08.14.11

McAfee
Trojan.Artemis!BB57FC5359EE
5600.7041

NANO AntiVirus
Riskware.Win32.MultiPlug.ddsvpv
0.28.2.61519

Panda Antivirus
PUP/TSUploader
14.08.12.09

Reason Heuristics
PUP.AlexeyKurilenko.K
14.8.12.9

Sophos
MultiPlug
4.98

VIPRE Antivirus
Threat.4150696
31208

File size:
650.4 KB (665,976 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\dosukoi.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
6/17/2014 5:20:17 AM

Valid to:
6/17/2015 5:20:17 AM

Subject:
E=Alexey.kurilenko@hotmail.com, CN=Alexey Kurilenko, O=Alexey Kurilenko, C=RU

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
15D51642691B3EE20985639A8FE865DD

File PE Metadata
Compilation timestamp:
8/6/2014 8:01:25 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:KZVunYav79cKnZxCAgX2QRkOSllkpGF57Lsth6RpoX/wR4u2/:Ysp9cWZVnQecI7Q+pOEE/

Entry address:
0xC461

Entry point:
E8, 3E, 3C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 10, 9F, 41, 00, E8, 19, 16, 00, 00, E8, 0B, 3E, 00, 00, 0F, B7, F0, 6A, 02, E8, D1, 3B, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, C4, 2C, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.8682  (probably packed)

Code size:
82.5 KB (84,480 bytes)

Remove dosukoi.exe - Powered by Reason Core Security