tbkqjalo.exe

KOMPANIYA КRЕАТА LLC

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file tbkqjalo.exe by KOMPANIYA КRЕАТА has been detected as adware by 32 anti-malware scanners. The program is a setup application that uses the Amonetize Downloader installer. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
KOMPANIYA КRЕАТА LLC  (signed and verified)

Version:
1.1.5.89

MD5:
b2680daf482f2cd7734ed84985681bd2

SHA-1:
cdb4303c5480e2f4c885c2b898e0f3412fd976cc

SHA-256:
9161c36fbdb353c28e2b8c9fdf25eb0fee20922d9c3fe78fcffec52889c377b9

Scanner detections:
32 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/14/2024 3:03:52 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Amonetize
7.1.1

AhnLab V3 Security
PUP/Win32.Amonetiz
2015.10.07

Avira AntiVirus
ADWARE/Amonetize.Z
8.3.2.2

Arcabit
Application.Bundler.Amonetize.N
1.0.0.576

avast!
Win32:Dropper-gen [Drp]
2014.9-151102

AVG
Toolbar
2016.0.2937

Bitdefender
Application.Bundler.Amonetize.N
1.0.20.1530

Bkav FE
W32.HfsAdware
1.3.0.7237

Comodo Security
UnclassifiedMalware
23366

Dr.Web
Adware.Downware.5913
9.0.1.0306

ESET NOD32
Win32/Amonetize.BI potentially unwanted (variant)
9.12365

Fortinet FortiGate
Adware/Amonetize
11/2/2015

F-Prot
W32/A-e6e0bf6a
v6.4.7.1.166

F-Secure
Application.Bundler.Amonetize
11.2015-02-11_2

G Data
Application.Bundler.Amonetize
15.11.25

K7 AntiVirus
Unwanted-Program
13.210.17440

Kaspersky
not-a-virus:AdWare.Win32.Amonetize
14.0.0.1182

McAfee
Artemis!B2680DAF482F
5600.6593

MicroWorld eScan
Application.Bundler.Amonetize.N
16.0.0.918

NANO AntiVirus
Riskware.Win32.Amonetize.dchxoa
0.30.26.3947

nProtect
Trojan-Clicker/W32.Amonetize.352992
15.10.06.01

Panda Antivirus
Trj/CI.A
15.11.02.02

Quick Heal
PUA.Amonetize.A5
11.15.14.00

Reason Heuristics
PUP.Amonetize.Bundler
15.11.2.14

Rising Antivirus
PE:Malware.RDM.31!5.25[F1]
23.00.65.151031

Sophos
Amonetize (PUA)
4.98

SUPERAntiSpyware
Adware.Amonetize/Variant
9532

Trend Micro House Call
TROJ_SPNV.03GP14
7.2.306

Trend Micro
TROJ_SPNV.03GP14
10.465.02

Vba32 AntiVirus
AdWare.Amonetize
3.12.26.4

VIPRE Antivirus
Amonetize
44332

Zillya! Antivirus
Adware.Amonetize.Win32.128
2.0.0.2431

File size:
344.7 KB (352,992 bytes)

Product version:
1.1.5.89

Original file name:
setup.exe

Bundler/Installer:
Amonetize Downloader

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\tbkqjalo.exe.part

Digital Signature
Authority:
Thawte, Inc.

Valid from:
6/15/2014 6:00:00 PM

Valid to:
6/16/2015 5:59:59 PM

Subject:
CN=KOMPANIYA КRЕАТА LLC, O=KOMPANIYA КRЕАТА LLC, L=Kharkiv, S=Kharkiv, C=UA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
04CA5D77531C0E61E4DE2CB0E6E4B5B2

File PE Metadata
Compilation timestamp:
7/17/2014 7:03:44 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:KBieRGukt2xUBTBIC+73uy1RFkWWfGuvB+bWjE2UES7igEU6:EvsN2xUBTIn0DJNS7iNU6

Entry address:
0x14C32

Entry point:
E8, E8, 5F, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 3C, 8E, 3F, 00, 00, 75, 18, E8, C8, 59, 00, 00, 6A, 1E, E8, 12, 58, 00, 00, 68, FF, 00, 00, 00, E8, 10, F6, FF, FF, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40, 50, 6A, 00, FF, 35, 3C, 8E, 3F, 00, FF, 15...
 
[+]

Entropy:
7.4444

Code size:
116.5 KB (119,296 bytes)

The file tbkqjalo.exe has been seen being distributed by the following URL.

Remove tbkqjalo.exe - Powered by Reason Core Security