app_setup.exe

Omicron Installer

DMN Partners SRL

The application app_setup.exe by DMN Partners SRL has been detected as a potentially unwanted program by 11 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Live__Soft__Action  (signed by DMN Partners SRL)

Product:
Omicron Installer

Version:
9.31.3.1

MD5:
eff10b6fef9efd12fbc25b9897d13fea

SHA-1:
b7e4a1d3cd76e3efb41b47983347cde1c88b45b4

SHA-256:
f5f70a6f452c3d0847a03302597fac2ea25c03ead007622742ea10385151e656

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/28/2024 3:54:23 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.GetNow
2015.08.05

Avira AntiVirus
PUA/GetNow.Gen
8.3.1.6

avast!
Win32:Trojan-gen
2014.9-151118

Dr.Web
Trojan.InstallCore.1139
9.0.1.0322

ESET NOD32
Win32/GetNow.I potentially unwanted (variant)
9.12044

herdProtect (fuzzy)
2015.11.18.12

K7 AntiVirus
Unwanted-Program
13.207.16784

Malwarebytes
PUP.Optional.Getnow
v2015.11.18.12

Reason Heuristics
PUP.DMNPartners.Installer (M)
15.9.16.12

Sophos
Live Soft Action (PUA)
4.98

VIPRE Antivirus
Trojan.Win32.Generic
42624

File size:
658.5 KB (674,312 bytes)

Product version:
9.31.3.1

Copyright:
(c) Live__Soft__Action. All rights reserved.

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\app_setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/12/2015 7:00:00 AM

Valid to:
6/12/2016 6:59:59 AM

Subject:
CN=DMN Partners SRL, O=DMN Partners SRL, STREET=Str Liviu Rebreanu 46-58, L=Bucharest, S=District 3, PostalCode=031793, C=RO

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
3EB036A1CA66096F2715D12685C107F3

File PE Metadata
Compilation timestamp:
7/29/2015 9:57:25 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:xlf17vYog0B4LpUBLd/TN6cJwozqiHSZvs+q350Obnoy90HS:xx17Yog0BlBd/TscJxmISZHG0zyIS

Entry address:
0x1A80B0

Entry point:
60, BE, 00, C0, 51, 00, 8D, BE, 00, 50, EE, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8915

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
564 KB (577,536 bytes)

Remove app_setup.exe - Powered by Reason Core Security