installer_microsoft_excel_english.exe

Vittalia Limited

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application installer_microsoft_excel_english.exe by Vittalia Limited has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. It is also typically executed from the user's temporary directory.
Publisher:
Vittalia Limited  (signed and verified)

MD5:
d8669105ae3dfac34baf3999d9dfa363

SHA-1:
01b8a8f082b716488b816c43ee010c353920433e

SHA-256:
4254b9c11a3fb5f6174b12537ad47f1602886c3271ae4baa16ee89a1a3b8bb67

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 10:05:01 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.180.228

AVG
InstallC
2015.0.3312

ESET NOD32
Win32/InstallCore.PL potentially unwanted application
7.0.302.0

K7 AntiVirus
Unwanted-Program
13.184.13741

NANO AntiVirus
Riskware.Win32.InstallCore.dddwte
0.28.2.62841

Qihoo 360 Security
Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.VittaliaLimited.b
14.10.23.21

Vba32 AntiVirus
3.12.26.3

VIPRE Antivirus
Threat.4782551
33706

File size:
746.2 KB (764,096 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\installer_microsoft_excel_english.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/18/2013 12:00:00 PM

Valid to:
5/18/2016 11:59:59 AM

Subject:
CN=Vittalia Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Vittalia Limited, L=Dublin, S=Dublin, C=IE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6CC8DB30E67B3DF9E2607EE882D390AC

File PE Metadata
Compilation timestamp:
6/20/1992 10:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:Skvpd0iCWpq2G0HRAEe7Jezvdo87dXN0PbVgnGhd/Do/EcTBYNY1DsPARwCOe548:SkvP0iC0q2G0xAP7Je5oij0DDsMcTNWI

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.8809

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

Remove installer_microsoft_excel_english.exe - Powered by Reason Core Security