m78binstaller.exe

Vittalia Limited

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application m78binstaller.exe by Vittalia Limited has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer.
Publisher:
Vittalia Limited  (signed and verified)

Version:
1.0.0.5

MD5:
1bc5ec5936ba874c3c7e817309670912

SHA-1:
6ef139b028375b7041ffd534bd48ec67a36427c9

SHA-256:
0b4b531c21bd224975324721f1ddc47ac0eea2d33de36da378860d35d0c0df8d

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
5/8/2024 1:58:08 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Vittalia
4.0.3.14916

Bitdefender
Gen:Variant.Kazy.418555
1.0.20.1095

Emsisoft Anti-Malware
Gen:Variant.Kazy.418555
8.14.08.07.01

ESET NOD32
Win32/Vittalia.R potentially unwanted application
8.7.0.302.0

G Data
Gen:Variant.Kazy.418555
14.8.24

herdProtect (fuzzy)
2014.10.1.5

IKARUS anti.virus
PUA.Vittalia
t3scan.1.6.1.0

McAfee
CryptVittalia
5600.7045

MicroWorld eScan
Gen:Variant.Kazy.418555
15.0.0.657

Reason Heuristics
PUP.VittaliaLimited.N
14.8.7.12

SUPERAntiSpyware
PUP.Vittalia/Variant
10436

VIPRE Antivirus
Threat.4782551
29708

File size:
845.1 KB (865,392 bytes)

Product version:
1.0.0.5

Copyright:
Copyright (C) 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Language:
Spanish

Common path:
C:\Documents and Settings\{user}\Application data\temp\m78binstaller.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/17/2013 7:30:00 PM

Valid to:
5/17/2016 7:29:59 PM

Subject:
CN=Vittalia Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Vittalia Limited, L=Dublin, S=Dublin, C=IE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6CC8DB30E67B3DF9E2607EE882D390AC

File PE Metadata
Compilation timestamp:
7/4/2014 8:27:54 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:UgnPDtT/NPqF+1/S6fAuyRY25YtiTIuXknWtyB:pdNPqgro5RbTIu0nWtyB

Entry address:
0x4B44D

Entry point:
E8, 42, 11, 01, 00, E9, 00, 00, 00, 00, 6A, 14, 68, F8, 9E, 4A, 00, E8, DD, 62, 00, 00, E8, 76, 52, 00, 00, 0F, B7, F0, 6A, 02, E8, D5, 10, 01, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, D6, D3, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
607.5 KB (622,080 bytes)

Remove m78binstaller.exe - Powered by Reason Core Security