odinv3.1.6.exe

The application odinv3.1.6.exe has been detected as a potentially unwanted program by 25 anti-malware scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from www.samsungodindownload.com and multiple other hosts.
MD5:
c5e7fcf5147ae92e840ab3a0c863758e

SHA-1:
7a8f2e2b2aea29d5a1cf819422304efb04479fb1

SHA-256:
6b8ecc8b3a1ec6708cc1dddacd1acda141a319e796962c209e5459acbcee72ef

Scanner detections:
25 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/6/2024 2:43:55 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Application.OutBrowse.J
564

Agnitum Outpost
PUA.OutBrowse
7.1.1

Avira AntiVirus
PUA/Outbrowse.Gen
8.3.1.6

Arcabit
Application.OutBrowse.J
1.0.0.425

avast!
NSIS:OutBrowse-BN [PUP]
2014.9-150720

AVG
Downloader
2016.0.3042

Baidu Antivirus
Adware.Win32.OutBrowse
4.0.3.15720

Bitdefender
Dropped:Application.OutBrowse.J
1.0.20.1005

Dr.Web
Trojan.Siggen6.33552
9.0.1.0201

ESET NOD32
Win32/OutBrowse potentially unwanted
9.11964

Fortinet FortiGate
Riskware/OutBrowse
7/20/2015

F-Secure
Application.OutBrowse.J
11.2015-20-07_2

G Data
Dropped:Application.OutBrowse
15.7.25

K7 AntiVirus
Adware
13.207.16606

Kaspersky
not-a-virus:Downloader.NSIS.OutBrowse
14.0.0.1707

Malwarebytes
Trojan.Agent
v2015.07.20.01

McAfee
Artemis!C5E7FCF5147A
5600.6698

MicroWorld eScan
Dropped:Application.OutBrowse.J
16.0.0.603

NANO AntiVirus
Trojan.Win32.DownLoad3.dqapeg
0.30.24.2487

Qihoo 360 Security
HEUR/QVM06.2.Malware.Gen
1.0.0.1015

Quick Heal
AdWare.OutBrowse.r5 (Not a Virus)
7.15.14.00

Trend Micro
TROJ_GE.AD134A21
10.465.20

Vba32 AntiVirus
Adware.Outbrowse
3.12.26.4

VIPRE Antivirus
OutBrowse
42154

Zillya! Antivirus
Downloader.OutBrowseGen.Win32.3
2.0.0.2300

File size:
782.2 KB (801,019 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\odinv3.1.6.exe

File PE Metadata
Compilation timestamp:
9/16/2008 9:17:44 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
12288:U5ONRvG9wrjUyJIGWFEtFjY47Rrdywj4hBCOtXEIGUPb60W/TQ6U+phLh7Xw:UIfeeluWfpdPFcJPbP2QYpBw

Entry address:
0x1000

Entry point:
E8, 6F, 2B, 00, 00, 50, E8, 73, 36, 01, 00, 00, 00, 00, 00, 90, 55, 8B, EC, 53, 56, 57, 8B, 7D, 10, 8B, 5D, 0C, 8B, 75, 08, 8B, D3, FF, 75, 14, 68, E5, 50, 41, 00, 6A, 00, 6A, 00, 8B, C6, 8B, CF, E8, 7A, 48, 00, 00, 81, EB, 10, 01, 00, 00, 74, 05, 4B, 74, 14, EB, 57, FF, 75, 14, 6A, 66, 56, E8, DE, 38, 01, 00, B8, 01, 00, 00, 00, EB, 47, 66, 81, E7, FF, FF, 66, FF, CF, 74, 07, 66, FF, CF, 74, 23, EB, 30, 68, 80, 00, 00, 00, 68, AC, 69, 41, 00, 6A, 65, 56, E8, 24, 38, 01, 00, 6A, 01, 56, E8, FE, 37, 01, 00...
 
[+]

Entropy:
7.9277  (probably packed)

Code size:
80 KB (81,920 bytes)

The file odinv3.1.6.exe has been seen being distributed by the following 2 URLs.

Remove odinv3.1.6.exe - Powered by Reason Core Security