omsi -editor.exe

MR-Software

The executable omsi -editor.exe has been detected as malware by 5 anti-virus scanners. This file is typically installed with the program OMSI 2 by MR-Software GbR. While running, it connects to the Internet address w0f.rzone.de on port 80 using the HTTP protocol.
Publisher:
MR-Software

Version:
2.0.14.0

MD5:
432fd1b4c2e148a45aa7107663e4f211

SHA-1:
5a8c2f726aec5dc2aa1a56fde4941dfcf42e9aec

SHA-256:
1b3376af85fc4066fe08c366f58152fca423f99a4475bcef37337816f6dd49c1

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
12/27/2024 5:59:47 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
2014.9-141005

Bkav FE
W32.HfsAutoB
1.3.0.4959

McAfee
Artemis!432FD1B4C2E1
5600.6844

nProtect
Trojan.Generic.11692958
14.11.28.01

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14704

File size:
8.3 MB (8,718,336 bytes)

Product version:
2.00

Copyright:
2014

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
1/22/2014 11:39:02 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:Ct6UAVsDnaedhBHK8QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQO:CQZVKaeNK8QQQQQQQQQQQQQQQQQQQQQM

Entry address:
0x7D12EE

Entry point:
53, 51, 52, 56, 57, 55, 8B, EC, 81, EC, 00, 10, 00, 00, C7, 45, 80, EC, 2A, BD, 00, 8B, 75, 80, B9, C0, 00, 00, 00, 8D, BD, 80, FC, FF, FF, F3, A5, 8D, 85, 80, FC, FF, FF, 89, 85, 74, FC, FF, FF, C7, 85, 44, FC, FF, FF, 78, 3C, 2B, 31, 8B, 85, 44, FC, FF, FF, 89, 85, 1C, FC, FF, FF, 8B, 85, 74, FC, FF, FF, 89, 85, 28, FC, FF, FF, B8, 00, 03, 00, 00, C1, E8, 02, 89, 85, 24, FC, FF, FF, 83, BD, 24, FC, FF, FF, 00, 7E, 4E, 8B, 85, 28, FC, FF, FF, 8B, 00, 89, 85, 20, FC, FF, FF, 8B, 85, 28, FC, FF, FF, 8B, 00...
 
[+]

Code size:
4.1 MB (4,298,752 bytes)

The file omsi -editor.exe has been discovered within the following program.

OMSI 2  by MR-Software GbR
www.omnibussimulator.de
About 6% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to w0f.rzone.de  (81.169.145.79:80)

Remove omsi -editor.exe - Powered by Reason Core Security