o2csetup.exe

ELECO Software GmbH

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is installed with o2c Player. The file has been seen being downloaded from www.deltawood.fr and multiple other hosts.
Publisher:
ELECO Software GmbH  (signed and verified)

MD5:
5b19a8df092087b8d88cc0d1b1c00a4e

SHA-1:
7cb21540a14133bcc113fcd9a8a2a5759b95cd8c

SHA-256:
cc365e49939727ac7ca8c1de6366e9548613c84c8156c7ca7801893e516fb06b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 3:50:28 AM UTC  (today)

File size:
6.1 MB (6,414,368 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\o2csetup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/10/2009 2:00:00 AM

Valid to:
7/31/2012 1:59:59 AM

Subject:
CN=ELECO Software GmbH, OU=o2c - objects to see, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ELECO Software GmbH, L=Hameln, S=Germany, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1C07C0EF9C0A9DCC3772AC2C3AC52FF9

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:weFIkcT++/CjPC73ixwknem/yJc/BM6qC:fukcT++1z4VneGyGpMBC

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file o2csetup.exe has been discovered within the following program.

o2c Player  by Eleco Software GmbH
www.o2c.de
About 5% of users remove it
 
Powered by Should I Remove It?

The file o2csetup.exe has been seen being distributed by the following 2 URLs.

http://www.deltawood.fr/.../O2CSetup.exe

Scan o2csetup.exe - Powered by Reason Core Security