setup_odm.exe

ODM

INSTALLER TECHNOLOGY CO.

This installer routine uses the Babylon network to include bundled offers of potentially unwanted programs (mostly search adware) such as toolbars and browser extensions. The application setup_odm.exe, “Open Downloader Manager” by INSTALLER TECHNOLOGY CO has been detected as a potentially unwanted program by 4 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from opendownloadmanager.com.
Publisher:
My Company  (signed by INSTALLER TECHNOLOGY CO.)

Product:
ODM

Description:
Open Downloader Manager

Version:
2.0.0.0

MD5:
d2b18addd6800c32b132a7bf4095a947

SHA-1:
425867ae3bb3d676885fbc41991b36aaea297ea7

SHA-256:
9742bd82a4d764cebf5cee70007a59339d47454061e21d11801492b7ba727de1

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 11:27:50 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Downware.1441
9.0.1.0240

Reason Heuristics
PUP.Installer.INSTALLERTECHNOLOGYCO.J
14.8.28.23

Trend Micro House Call
TROJ_GEN.F47V0911
7.2.240

VIPRE Antivirus
InstallerTech
21878

File size:
456.6 KB (467,520 bytes)

Copyright:
Free Author © 2013

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup_odm.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/4/2012 6:00:00 PM

Valid to:
10/6/2013 5:59:59 PM

Subject:
CN=INSTALLER TECHNOLOGY CO., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=INSTALLER TECHNOLOGY CO., L=Miami, S=Florida, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
61DB0858B233331E32FD2CE3F0C5CD55

File PE Metadata
Compilation timestamp:
12/5/2009 3:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:xIIPNnnmdPVlHBeZ19RbNm2K85GK7x+wTe/7RrC+:xIIPNnml4Z1HlNrl+FZC+

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8781

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file setup_odm.exe has been seen being distributed by the following URL.

Remove setup_odm.exe - Powered by Reason Core Security