setup_open_office.exe

Open Office

Install Helper

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup_open_office.exe by Install Helper has been detected as adware by 25 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from dl.1download.io.
Publisher:
Install Helper  (signed and verified)

Product:
Open Office

Version:
3.0.0.82

MD5:
4b1fe2b39c527e85b39d2fa137a426c7

SHA-1:
527290d7f4cb9abc1f007091492d35237c88d7fe

SHA-256:
f1f5c298e3698efce203f6daa594044902ad7206d2d062f3351788e1bd74cdc2

Scanner detections:
25 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
1/13/2025 12:44:49 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.AirInstaller.5
5745241

AhnLab V3 Security
PUP/Win32.InstallHelper
2015.06.18

Avira AntiVirus
TR/Crypt.XPACK.Gen
8.3.1.6

Arcabit
Trojan.Application.Bundler.AirInstaller.5
1.0.0.425

avast!
Win32:Adware-CKN [PUP]
150602-1

AVG
Generic
2016.0.3075

Bitdefender
Gen:Variant.Application.Bundler.AirInstaller.5
1.0.20.840

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.DownloadAssistant.S
22483

Dr.Web
Trojan.Vittalia.30
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.AirInstaller
10.0.0.5366

ESET NOD32
Win32/DownloadAssistant.A potentially unwanted application
7.0.302.0

F-Prot
W32/Dlhelper.D.gen
v6.4.7.1.166

F-Secure
Riskware.Gen:Variant.Application.Bundler
5.14.151

G Data
Gen:Variant.Application.Bundler.AirInstaller
15.6.25

K7 AntiVirus
Unwanted-Program
13.205.16276

MicroWorld eScan
Gen:Variant.Application.Bundler.AirInstaller.5
16.0.0.504

NANO AntiVirus
Trojan.Win32.Vittalia.dowmzz
0.30.24.2086

Norman
Gen:Variant.Application.Bundler.AirInstaller.5
02.06.2015 14:23:46

Panda Antivirus
Trj/Genetic.gen
15.06.17.04

Reason Heuristics
PUP.Vittalia.Bundler
15.6.17.12

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.15615

Sophos
PUA 'AirInstaller'
5.15

Vba32 AntiVirus
Downloader.DownloadHelper
3.12.26.4

VIPRE Antivirus
AirInstaller
41214

File size:
838.2 KB (858,280 bytes)

Product version:
3.0.0.82

Copyright:
(c) Install Helper

Original file name:
setup_open_office.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup_open_office.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
1/29/2015 12:00:00 AM

Valid to:
1/29/2016 11:59:59 PM

Subject:
CN=Install Helper, O=Install Helper, L=Vancouver, S=British Columbia, C=CA

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
7CC3624C218D0B5B8DB87F5E4E3521B0

File PE Metadata
Compilation timestamp:
2/26/2015 1:08:17 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:L6QXxQuGgKZG38Y8jH6xzOlwILwaYdHYNE:Bjx2Hmag/HYNE

Entry address:
0x126A

Entry point:
55, 8B, EC, 83, EC, 10, 53, 56, 57, 6A, 00, FF, 15, 08, 80, 47, 00, 8B, F8, 33, D2, 8B, CF, 8B, 5F, 3C, 03, DF, 2B, 05, 1C, 10, 40, 00, 89, 45, F4, 1B, D2, F7, D8, 89, 55, F8, 0F, B7, 73, 14, 83, D2, 00, F7, DA, 89, 75, F0, 52, 8B, 93, A0, 00, 00, 00, 50, 8B, 44, 1E, 24, 03, 05, 28, 10, 40, 00, 50, FF, B3, A4, 00, 00, 00, E8, 88, FD, FF, FF, 8B, 54, 1E, 28, 83, C4, 10, A1, 28, 10, 40, 00, 2B, D0, 83, FA, 01, 76, 0D, 8B, 4C, 1E, 24, 03, C8, 03, CF, E8, F2, FE, FF, FF, A1, 20, 10, 40, 00, 83, C6, 40, 03, F3...
 
[+]

Entropy:
7.0624

Developed / compiled with:
Microsoft Visual C++

Code size:
474.5 KB (485,888 bytes)

The file setup_open_office.exe has been seen being distributed by the following URL.

Remove setup_open_office.exe - Powered by Reason Core Security