PUA.OneKit also known as Trojan ( 0049c6a11 ), BubbleDock (fs).
Malware Analysis of PUA.OneKit – C16CINSTALLER.EXE
Created files:
%Local Appdata%\temp\c16cfondo.bmp
%Local Appdata%\temp\c16cheader.bmp
%Local Appdata%\temp\c16cInstaller.exe
%Local Appdata%\temp\c16cInstaller.INI
%Temp%\3dboxes_pcspeedup.bmp
Detected by UnHackMe:
C16CINSTALLER.EXE
Default location: %LOCAL APPDATA%\TEMP\C16CINSTALLER.EXE
Dropper hash(md5): 404b7cb0f00799c1cf1e9f5e7a4e3ef8