foofind-download-manager_0.2-20140318.exe

One Installer LLC

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application foofind-download-manager_0.2-20140318.exe by One Installer has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. While running, it connects to the Internet address oneinstaller.com on port 80 using the HTTP protocol.
Publisher:
One Installer LLC  (signed and verified)

MD5:
6a9077816f70501aa2ac71d405cc42ad

SHA-1:
3324ef72d91a8cb445fd63536279afe7d96388e9

SHA-256:
65934f321c344b8adc4b46d5775a683973e4d9a4bc52f3a737b3e881f58c7502

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/27/2024 12:26:24 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Adware/Win32.Lollipop
15.09.19

Dr.Web
Trojan.Packed.25820
9.0.1.0262

ESET NOD32
Win32/OneInstaller
9.9628

Malwarebytes
PUP.Optional.OneInstaller
v2015.09.19.01

NANO AntiVirus
Riskware.Nsis.Downloader.cuognw
0.28.0.58873

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Reason Heuristics
PUP.Vittalia.OneInstaller (M)
15.9.19.13

Sophos
Lollipop
4.98

SUPERAntiSpyware
Adware.Lollipop/Variant
9620

Trend Micro House Call
TROJ_GE.AB7A481A
7.2.262

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

VIPRE Antivirus
Vittalia Installer
27960

File size:
162.2 KB (166,104 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\foofind-download-manager_0.2-20140318.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
11/6/2013 10:20:03 AM

Valid to:
6/24/2016 12:26:08 PM

Subject:
CN=One Installer LLC, O=One Installer LLC, L=Wilmington, S=Delaware, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
280F69FCB8F054

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:fgXdZt9P6D3XJC4BIl0CXchZme75+wITUi2jUzK93iMknyWJt4kycPlO4:fe34g2CMh9JITIUza5knnJukycPlJ

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.5908

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to oneinstaller.com  (93.189.35.51:80)

Remove foofind-download-manager_0.2-20140318.exe - Powered by Reason Core Security