installer_flv_media_player__portuguese.exe

Onekit Internet S,L

The application installer_flv_media_player__portuguese.exe by Onekit Internet S,L has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the OneKit Downloader installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from mediaplayer2.begin.pro.
Publisher:
Onekit Internet S,L  (signed and verified)

MD5:
360fcfb255a23c0bf24c7eac08c2fc23

SHA-1:
60182e80ceffc7fc16dc9a968a3deae23ded1cb8

SHA-256:
140fcf67cd66c5e284839b7214cd7496d855e84dd0cfe24c08d5a8e60c2379be

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/26/2024 6:22:53 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.166.34

AVG
InstallC
2015.0.3388

ESET NOD32
Win32/InstallCore.PL potentially unwanted application
8.7.0.302.0

IKARUS anti.virus
PUA.Vittalia
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.183.12998

Malwarebytes
PUP.Optional.Onekit.A
v2014.08.09.12

McAfee
Adware-DomaIQ
5600.7044

NANO AntiVirus
Riskware.Win32.InstallCore.dddwte
0.28.2.61349

Qihoo 360 Security
Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.OnekitInternetSL.g
14.8.8.22

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Threat.4786531
31208

File size:
861.8 KB (882,448 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OneKit Downloader (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\installer_flv_media_player__portuguese.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/15/2013 2:25:37 PM

Valid to:
5/18/2016 8:11:52 AM

Subject:
E=info@onekit.com, CN="Onekit Internet S,L", O="Onekit Internet S,L", L=Cerdanyola Del Valles, S=Barcelona, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11216C6B688869B7980323D94C3965BBB528

File PE Metadata
Compilation timestamp:
12/5/2009 8:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:usHDRJ5/qws+LENhTxoSvfGMQ8pLOWGmGGkwjC1+/WNJTvx:7DRJ5/qwsqEbXHmSLO92egkVx

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installer_flv_media_player__portuguese.exe has been seen being distributed by the following URL.

Remove installer_flv_media_player__portuguese.exe - Powered by Reason Core Security