ovisetup.exe

OpenIV

New Technology Studio

This is a setup and installation application. The file has been seen being downloaded from ntscorp.ru and multiple other hosts.
Publisher:
New Technology Studio

Product:
OpenIV

Description:
OpenIV setup

Version:
2.0.0.0

MD5:
a745aaa4f471575e5d4096c2927972f8

SHA-1:
3abbeab3b57083136b289e95f7bea08e16a4e541

SHA-256:
716de8c4186f537dbcc6199492c8f0f37a21d5ea17379d4a2bc44fe965dbeb53

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/15/2024 4:02:15 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Genome
2015.01.22

File size:
5.3 MB (5,599,744 bytes)

Product version:
2.0.0.0

Copyright:
© New Technology Studio

Original file name:
ovisetup.exe

File type:
Executable application (Win32 EXE)

Language:
Rusça (Rusya)

Common path:
C:\users\{user}\downloads\ovisetup.exe

File PE Metadata
Compilation timestamp:
1/15/2015 8:06:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:Mn6QK5gBJB6yET5mSHukNK+bC8jPuzpntq2TJMwZiTgnpJxJ98UK3JzSMadEYJfX:4payv+bCuPKqmnptmSMadxfcjFVpPm

Entry address:
0x31A400

Entry point:
55, 8B, EC, 83, C4, EC, 53, 56, 57, 33, C0, 89, 45, EC, B8, 18, D6, 70, 00, E8, 8C, 3D, CF, FF, 33, C0, 55, 68, C3, A4, 71, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 89, A4, 71, 00, 64, FF, 32, 64, 89, 22, A1, 24, 70, 6E, 00, E8, 72, CD, FC, FF, A1, 24, 70, 6E, 00, E8, 60, D4, FC, FF, 84, C0, 74, 0C, A1, 24, 70, 6E, 00, E8, 3A, D3, FC, FF, EB, 27, 68, E0, A4, 71, 00, 6A, 10, 8D, 55, EC, A1, 4C, 83, 72, 00, 8B, 00, E8, 56, FA, EC, FF, 8B, 4D, EC, A1, 4C, 83, 72, 00, 8B, 00, 33, D2, E8, 3D, E6, EF, FF, 33...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3.1 MB (3,248,640 bytes)

The file ovisetup.exe has been seen being distributed by the following 2 URLs.

Scan ovisetup.exe - Powered by Reason Core Security