onlysetup.exe

Key to Search LTD

The application onlysetup.exe by Key to Search has been detected as adware by 25 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory.
Publisher:
Pay By Ads LTD  (signed by Key to Search LTD)

Version:
1.3.0.0

MD5:
7e11dd2662065887033fe4499be7dfa6

SHA-1:
b923970dcf9a2fd5dad0b2c535d73e921e9ab6f3

SHA-256:
a0bfa854d352a2562e07e46b651065f1e7267918f8ce275505050e4599c86549

Scanner detections:
25 / 68

Status:
Adware

Analysis date:
12/29/2024 12:57:01 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.PayByAds.2
524

AhnLab V3 Security
PUP/Win32.PayByAds
2015.07.14

Arcabit
Trojan.Adware.PayByAds.2
1.0.0.425

AVG
AdPlugin
2016.0.3002

Baidu Antivirus
PUA.Win32.Montiera
4.0.3.15830

Bitdefender
Gen:Variant.Adware.PayByAds.2
1.0.20.1210

Dr.Web
Adware.Toolbar.638
9.0.1.0242

Emsisoft Anti-Malware
Gen:Variant.Adware.PayByAds
8.15.08.30.02

ESET NOD32
Win32/Toolbar.Montiera.R potentially unwanted (variant)
9.11932

Fortinet FortiGate
Riskware/Montiera
8/30/2015

F-Secure
Gen:Variant.Adware.PayByAds
11.2015-30-08_1

G Data
Gen:Variant.Adware.PayByAds
15.8.25

IKARUS anti.virus
PUA.Toolbar.Montiera
t3scan.1.9.5.0

K7 AntiVirus
Adware
13.205.16545

Malwarebytes
PUP.Optional.OnlySearch.A
v2015.08.30.02

McAfee
Artemis!7E11DD266206
5600.6658

MicroWorld eScan
Gen:Variant.Adware.PayByAds.2
16.0.0.726

NANO AntiVirus
Trojan.Win32.Montiera.dsokuj
0.30.24.2487

Panda Antivirus
Trj/Genetic.gen
15.08.30.02

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Win32.Generic.Montiera.Installer.Meta
15.8.30.2

Trend Micro
TROJ_GEN.R08NC0OFI15
10.465.30

Vba32 AntiVirus
Downloader.Montiera
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
41968

Zillya! Antivirus
Downloader.Montiera.Win32.84
2.0.0.2286

File size:
446.4 KB (457,112 bytes)

Copyright:
All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\onlysetup.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
5/17/2015 9:00:00 PM

Valid to:
5/17/2016 9:00:00 AM

Subject:
CN=Key to Search LTD, O=Key to Search LTD, L=Tel Aviv, C=IL

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
06477BB277C3DCF813C68101CCDEE2DD

File PE Metadata
Compilation timestamp:
5/20/2015 2:08:49 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:PB+aJbEcbRlZgC0k1MG0gC6WO0EGIdRaRc9ssc:KG0F6WO0EGIyRca/

Entry address:
0x36D2A

Entry point:
E8, 65, 84, 00, 00, E9, 89, FE, FF, FF, B8, D9, FC, 43, 00, A3, E0, 43, 46, 00, C7, 05, E4, 43, 46, 00, CF, F3, 43, 00, C7, 05, E8, 43, 46, 00, 83, F3, 43, 00, C7, 05, EC, 43, 46, 00, BC, F3, 43, 00, C7, 05, F0, 43, 46, 00, 25, F3, 43, 00, A3, F4, 43, 46, 00, C7, 05, F8, 43, 46, 00, 51, FC, 43, 00, C7, 05, FC, 43, 46, 00, 41, F3, 43, 00, C7, 05, 00, 44, 46, 00, A3, F2, 43, 00, C7, 05, 04, 44, 46, 00, 2F, F2, 43, 00, C3, 8B, FF, 55, 8B, EC, E8, 96, FF, FF, FF, 83, 7D, 08, 00, 74, 05, E8, 53, 8F, 00, 00, DB...
 
[+]

Code size:
310 KB (317,440 bytes)

Remove onlysetup.exe - Powered by Reason Core Security