Setup.exe

Onekit Internet

The file Setup.exe by Onekit Internet has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the OneKit Downloader installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
Onekit Internet  (signed and verified)

MD5:
bd86dfb465e08c1b0f8d25a832a99883

SHA-1:
0739f06d5cccd7f51049220438c4a09f4d194fd2

SHA-256:
3553eeba7cc9485d3e3e56555369fadb3449bcdd56f01f725d1732b16fcb57ea

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 5:56:50 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Evo-gen [Susp]
150525-2

AVG
Onenet
2016.0.3096

Dr.Web
Trojan.Vittalia.34
9.0.1.05190

ESET NOD32
Win32/TrojanDropper.Addrop.C trojan
7.0.302.0

Malwarebytes
v2015.05.27.12

Reason Heuristics
PUP.Installer.OnekitInternet
15.6.7.12

VIPRE Antivirus
Threat.4783369
40552

File size:
806 KB (825,360 bytes)

Bundler/Installer:
OneKit Downloader (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
3/4/2015 7:00:00 PM

Valid to:
3/4/2016 6:59:59 PM

Subject:
CN=Onekit Internet, O=Onekit Internet, L=Cerdanyola del valles, S=Barcelona, C=ES

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
40744793F55F4350CB4D2F030795E67F

File PE Metadata
Compilation timestamp:
12/5/2009 5:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:PULca8sxTn0WXk+0fPpbyb/VPrtLixFEBqeV8/QblnRNFoO5lYojOksmlAx3:PjKj0tDPZutPJMF9QbbNFoloZ6x3

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9871

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove Setup.exe - Powered by Reason Core Security