oxyinst.exe

Fast File Downloader

SOFTWARE AGILITY LIMITED

The application oxyinst.exe by SOFTWARE AGILITY LIMITED has been detected as adware by 29 anti-malware scanners. This is the uninstaller utility registered in the Windows Control Panel for the program Oxy by AGILITY. According to AVG, this software downloads additional adware offers during setup.
Publisher:
SOFTWARE AGILITY LIMITED  (signed and verified)

Product:
Fast File Downloader

Version:
1,0,1,3096

MD5:
00e1018fba972eb12f7e3adeec2d0d3b

SHA-1:
70ce989e1ed6bc2f42d0a458dd45d167f0d64551

SHA-256:
977fafa3e991666106f5083fa2e12cde96b245b391590f56036b17910d4e4bde

Scanner detections:
29 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Analysis date:
4/26/2024 10:05:55 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.126981
364

AegisLab AV Signature
Troj.Dropper.W32.Agent
2.1.4+

Agnitum Outpost
Trojan.DR.Agent
7.1.1

Avira AntiVirus
ADWARE/Adware.Gen
7.11.154.134

avast!
Win32:Adware-gen [Adw]
2014.9-160206

AVG
Trojan horse Downloader.Generic13
2017.0.2842

Baidu Antivirus
Adware.Win32.BundleInstaller
4.0.3.1626

Bitdefender
Gen:Variant.Adware.Graftor.126981
1.0.20.185

Clam AntiVirus
Win.Adware.Agent-15250
0.98/19479

Dr.Web
Adware.Downware.2160
9.0.1.037

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.126981
8.16.02.06.02

ESET NOD32
Win32/BundleInstaller.D potentially unwanted application
10.7.0.302.0

Fortinet FortiGate
W32/Agent.PFR!tr
2/6/2016

F-Prot
W32/A-6e1bfd6d
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Graftor.126981
11.2016-06-02_7

G Data
Gen:Variant.Adware.Graftor.126981
16.2.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.183.13584

Kaspersky
not-a-virus:Downloader.Win32.Agent
14.0.0.704

Malwarebytes
PUP.Optional.BundleInstaller.A
v2016.02.06.02

Microsoft Security Essentials
Threat.Undefined
1.177.2346.0

MicroWorld eScan
Gen:Variant.Adware.Graftor.126981
17.0.0.111

NANO AntiVirus
Riskware.Win32.Downware.dbmliy
0.28.0.60577

Norman
Gen:Variant.Adware.Graftor.126981
11.20160206

Panda Antivirus
Trj/Genetic.gen
16.02.06.02

Reason Heuristics
PUP.SOFTWAREAGILITY (M)
16.2.6.2

Rising Antivirus
PE:Malware.Adware!6.17C6
23.00.65.16204

Vba32 AntiVirus
TrojanDropper.Agent
3.12.26.3

Zillya! Antivirus
Downloader.Agent.Win32.200769
2.0.0.1857

File size:
6.1 MB (6,447,064 bytes)

Product version:
1,0,1,3096

Copyright:
Copyright 2013

Original file name:
Oxy.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\oxy\oxyinst.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/30/2014 2:00:00 AM

Valid to:
5/1/2015 1:59:59 AM

Subject:
CN=SOFTWARE AGILITY LIMITED, OU=SOFTWARE AGILITY LIMITED, O=SOFTWARE AGILITY LIMITED, POBox=DE11 9RY, STREET="5 NAPIER CLOSE,CHURCH GRESLEY", L=SWADLINCOTE, S=DERBYSHIRE, PostalCode=DE11 9RY, C=GB

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B52D3D8F2E42BA756476350F1569C2A5

File PE Metadata
Compilation timestamp:
7/18/2014 7:23:49 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:RfOJasEOqZSER+0SrKCyd+G4UbqxvD2AiKZyKKi:RfO4HPgr2XbwvD2AfxKi

Entry address:
0xC7DD7

Entry point:
E8, 43, A1, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, E5, 06, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A0, 01, 00, 00, 81, F9, 80, 00, 00, 00, 72, 1C, 83, 3D, C4, AB, 51, 00, 00, 74, 13, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 05, E9, 76, A1, 00, 00, F7, C7, 03, 00, 00, 00, 75, 14, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 29...
 
[+]

Entropy:
5.2025

Code size:
962.5 KB (985,600 bytes)

Program Uninstaller
Program name:
Oxy

Display publisher:
AGILITY

Uninstall string:
"C:\users\{user}\appdata\roaming\oxy\oxyinst.exe" --uninstall


Remove oxyinst.exe - Powered by Reason Core Security