dlnow_setup_oc.exe

DLnow

Logixoft

The application dlnow_setup_oc.exe, “DLnow Setup Program” by Logixoft has been detected as adware by 5 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from files.downloadnow.com and multiple other hosts.
Publisher:
Logixoft  (signed and verified)

Product:
DLnow

Description:
DLnow Setup Program

Version:
1

MD5:
00064a67b479914a0863f58f905b2182

SHA-1:
672becc9414b3394b32ca305effb48193e444603

SHA-256:
63f80a4748aa9ebe2ee825244fbd06dbf49b6f0f1f7454db47771b900c112ca8

Scanner detections:
5 / 68

Status:
Adware

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
4/24/2024 12:52:34 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Dr.Web
Adware.OpenCandy.144
9.0.1.0201

ESET NOD32
Win32/OpenCandy.A potentially unsafe (variant)
9.11942

Fortinet FortiGate
Riskware/OpenCandy
7/20/2015

Reason Heuristics
PUP.Logixoft.Installer (M)
15.7.20.20

File size:
1.1 MB (1,150,024 bytes)

Product version:
1

Copyright:
Copyright © Logixoft

Original file name:
DLnowSetup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\dlnow_setup_oc.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/11/2013 3:00:00 AM

Valid to:
4/11/2016 2:59:59 AM

Subject:
CN=Logixoft, O=Logixoft, STREET="14, rue Marie-Rose le Bloch", L=QUIMPER, S=Bretagne, PostalCode=29000, C=FR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5B18B568174DC2D647EC70ED13CCBB8D

File PE Metadata
Compilation timestamp:
5/15/2015 7:47:51 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:HhDZeAf5GzGQLyAxkKT/dPyuK0G7KxCzU6oGm8O661jbqqfgBpM:ZZZALRmKT/4Bl+xfGQ661jBqpM

Entry address:
0x57084

Entry point:
E8, 65, 98, 00, 00, E9, 79, FE, FF, FF, CC, CC, 68, 60, 6C, 45, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, AC, A2, 49, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 6A, 0C, 68, 78, 1A, 49, 00, E8, 9B, FF, FF, FF, 6A, 0E, E8, BC, 22, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08...
 
[+]

Entropy:
7.2457

Code size:
498.5 KB (510,464 bytes)

The file dlnow_setup_oc.exe has been seen being distributed by the following 2 URLs.

Remove dlnow_setup_oc.exe - Powered by Reason Core Security