Setup.exe

Onekit Internet

The file Setup.exe by Onekit Internet has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the OneKit Downloader installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
Onekit Internet  (signed and verified)

MD5:
2b0728a09c343b6e602e2ad6ea961b67

SHA-1:
8e107c2f0b077f544580621ea6ad16bb1bdbd643

SHA-256:
3f3ce68c4c3a110e466c5dfc0f8765be7745d1cf6c5450a083ae0dc5334f3e3b

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/26/2024 10:08:10 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Onenet
2016.0.3101

Dr.Web
Trojan.Vittalia.34
9.0.1.05190

ESET NOD32
Win32/TrojanDropper.Addrop.C trojan
7.0.302.0

Malwarebytes
v2015.05.23.10

Reason Heuristics
PUP.Installer.OnekitInternet
15.6.7.12

VIPRE Antivirus
Threat.4783369
40432

File size:
1.3 MB (1,402,912 bytes)

Bundler/Installer:
OneKit Downloader (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
3/5/2015 10:00:00 AM

Valid to:
3/5/2016 9:59:59 AM

Subject:
CN=Onekit Internet, O=Onekit Internet, L=Cerdanyola del valles, S=Barcelona, C=ES

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
40744793F55F4350CB4D2F030795E67F

File PE Metadata
Compilation timestamp:
12/6/2009 8:52:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:x/+PwRLjS0qUsgiahzCpwQ+W+B/25pBnQIMKoqxiC8fYSnmF2FjIopCS:sYA0qUsxtaQt+BOtLMKoFzfhmF2FjBpz

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9925

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove Setup.exe - Powered by Reason Core Security