openofficesuite-setup.exe

Trusted Install Software

The application openofficesuite-setup.exe by Trusted Install Software has been detected as adware by 29 anti-malware scanners. The program is a setup application that uses the Tomorrow Software Installer installer. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages. With this installer, users are expecting to download the free Apache OpenOffice but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Modern New Installer  (signed by Trusted Install Software)

Product:
Modern New Installer

Version:
33.9.8.1085

MD5:
c0335740349a78334be7c6a5b12f5205

SHA-1:
171dbffbb87bda30a6c4c20fe6347a0ce72e9c39

SHA-256:
c09edd03ac1bdd334fd11b8a375699c57c775818ccf0b83ab8a838f0a10f047f

Scanner detections:
29 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 3:38:36 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.DownloadAdmin.4
454

Agnitum Outpost
Trojan.Vittalia
7.1.1

AhnLab V3 Security
PUP/Win32.DownloadAdmin
2015.11.06

Avira AntiVirus
PUA/DownloadAdmin.LG
8.3.2.2

avast!
Win32:Malware-gen
2014.9-151108

AVG
Generic
2016.0.2932

Baidu Antivirus
PUA.Win32.DownloadAdmin
4.0.3.15118

Bitdefender
Gen:Variant.Application.Bundler.DownloadAdmin.4
1.0.20.1560

Bkav FE
W32.HfsAdware
1.3.0.7383

Clam AntiVirus
Win.Trojan.Agent-950070
0.98/21511

Dr.Web
Trojan.Vittalia.758
9.0.1.0312

Emsisoft Anti-Malware
Gen:Variant.Symmi.6376
8.15.11.08.07

ESET NOD32
Win32/DownloadAdmin.P potentially unwanted (variant)
9.12522

Fortinet FortiGate
Riskware/DownloadAdmin
11/8/2015

F-Prot
W32/S-3bfe598a
v6.4.7.1.166

F-Secure
Gen:Variant.Symmi.6376
11.2015-08-11_1

G Data
Gen:Variant.Application.Bundler.DownloadAdmin
15.11.25

IKARUS anti.virus
Trojan.Symmi
t3scan.1.9.5.0

K7 AntiVirus
Adware
13.212.17765

Malwarebytes
PUP.Optional.DownLoadAdmin
v2015.11.08.07

McAfee
Artemis!F230A2F95D77
5600.6588

Microsoft Security Essentials
SoftwareBundler:Win32/Dowadmin
1.1.12205.0

MicroWorld eScan
Gen:Variant.Application.Bundler.DownloadAdmin.4
16.0.0.936

NANO AntiVirus
Trojan.Win32.Vittalia.dyeimz
0.30.26.4437

Reason Heuristics
PUP.TomorrowSoftware.TrustedInstallSoftware.Installer (M)
15.11.8.7

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.151106

Sophos
Download Admin (PUA)
4.98

VIPRE Antivirus
Trojan.Win32.Generic
45032

Zillya! Antivirus
Adware.BrowseFox.Win32.122615
2.0.0.2496

File size:
866.8 KB (887,576 bytes)

Product version:
33.9.8.1085

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tomorrow Software Installer

Language:
English (United States)

Common path:
C:\users\{user}\downloads\openofficesuite-setup.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
9/16/2015 8:38:38 PM

Valid to:
9/16/2016 8:38:38 PM

Subject:
CN=Trusted Install Software, O=Trusted Install Software, L=San Francisco, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00E2AD3DC1CBA6ED41

File PE Metadata
Compilation timestamp:
9/18/2014 10:51:11 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:arSup16n3t3JEWx3Dt/Bmx7ZeiyXxUcdEKCt:Spg3jd9vc4iC7C

Entry address:
0x1E62

Entry point:
E8, 19, BA, 00, 00, E9, 1B, B3, 00, 00, CC, CC, CC, CC, 81, EC, BC, 00, 00, 00, 8B, 94, 24, CC, 00, 00, 00, 53, 8B, 9C, 24, D8, 00, 00, 00, 55, 8B, AC, 24, CC, 00, 00, 00, 56, 8B, B4, 24, DC, 00, 00, 00, 57, 8B, BC, 24, D8, 00, 00, 00, 8B, 07, 03, C5, 89, 44, 24, 1C, 8B, 03, 8D, 0C, 30, 89, 4C, 24, 34, 8B, 8C, 24, E8, 00, 00, 00, 83, E1, 04, C7, 44, 24, 18, FF, FF, FF, FF, 89, 6C, 24, 10, 89, 74, 24, 20, 89, 4C, 24, 38, 74, 05, 83, C8, FF, EB, 06, 2B, C2, 8D, 44, 30, FF, 8D, 48, 01, 89, 44, 24, 3C, 89, 4C...
 
[+]

Entropy:
7.9687  (probably packed)

Code size:
52.5 KB (53,760 bytes)

The file openofficesuite-setup.exe has been seen being distributed by the following URL.

Remove openofficesuite-setup.exe - Powered by Reason Core Security