downlite_setup.exe

DownLite Installer

OOO

The application downlite_setup.exe by OOO has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from downlite.net.
Publisher:
DownLite  (signed by OOO )

Product:
DownLite Installer

Version:
1.0.1.1

MD5:
d68819d460c74d66c0018ecc25a93b18

SHA-1:
508065d3447503ea7ae953478e4079abe97d94c0

SHA-256:
e27255bef33a7e6dd1b4a2ebba7acc6eea03232dfbadb831b2fb178318ad1613

Scanner detections:
7 / 68

Status:
Adware

Analysis date:
4/23/2024 11:59:56 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
2014.9-140120

Dr.Web
Adware.Downware.1329
9.0.1.0359

ESET NOD32
Win32/DownLite
7.9190

Reason Heuristics
PUP.Installer.OOO.O
14.2.20.16

Trend Micro House Call
TROJ_GEN.F47V0723
7.2.359

VIPRE Antivirus
Adware.Privitize
24908

ViRobot
Trojan.Win32.Agent.87672
2011.4.7.4223

File size:
2 MB (2,083,408 bytes)

Product version:
1.0.1.1

Copyright:
Copyright 2013

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\downlite_setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/2/2012 3:00:00 AM

Valid to:
8/3/2015 2:59:59 AM

Subject:
CN="OOO ""Industry""", O="OOO ""Industry""", STREET="Vsevolzhsky 2, bld. 2", L=Moscow, S=Moscow, PostalCode=119034, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D139BDA20096871840DCE08E6A80B6F0

File PE Metadata
Compilation timestamp:
12/6/2009 1:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:gtlIIcrg2+j5r2Qnn+zpNs2+mMXhxGnXFW/dbQY:2INl+NVSpC2+Tcgdbr

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8857

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file downlite_setup.exe has been seen being distributed by the following URL.

Remove downlite_setup.exe - Powered by Reason Core Security