Setup.exe

Onekit Internet

The file Setup.exe by Onekit Internet has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the OneKit Downloader installer. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser. The file has been seen being downloaded from zotit74663roquj.kiqecaruree.info.
Publisher:
Onekit Internet  (signed and verified)

MD5:
2be3c9d66a75a180168cd527147d553b

SHA-1:
2ec674be4c2209d34afcbed877f3a56dd2c09174

SHA-256:
1a579941524ba33a75088da75a21ec581fc675b24acfef9e46c93eb477872ce2

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
8/8/2025 1:42:21 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Malware-gen
150319-1

AVG
Onenet
2016.0.3123

Comodo Security
UnclassifiedMalware
21953

Dr.Web
Trojan.Vittalia.34
9.0.1.05190

ESET NOD32
Win32/TrojanDropper.Addrop.C trojan
7.0.302.0

Reason Heuristics
PUP.Installer.OnekitInternet
15.6.7.12

VIPRE Antivirus
Threat.4783369
39676

File size:
813.5 KB (833,048 bytes)

Bundler/Installer:
OneKit Downloader (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
3/4/2015 6:00:00 PM

Valid to:
3/4/2016 5:59:59 PM

Subject:
CN=Onekit Internet, O=Onekit Internet, L=Cerdanyola del valles, S=Barcelona, C=ES

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
40744793F55F4350CB4D2F030795E67F

File PE Metadata
Compilation timestamp:
12/5/2009 4:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:cfRhzghPl05DOr3EznEMhRtXRGQ51lfK9u:uDoPa5DOjEFrF1lyu

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9874

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file Setup.exe has been seen being distributed by the following URL.

Remove Setup.exe - Powered by Reason Core Security