301.42-desktop-win7-winvista-64bit-international-whql.exe

NVIDIA Windows Display Driver Installer

NVIDIA Corporation

This is a setup and installation application. The file has been seen being downloaded from kr.download.nvidia.com and multiple other hosts.
Publisher:
NVIDIA Corporation  (signed and verified)

Product:
NVIDIA Windows Display Driver Installer

Version:
1, 0, 0, 0

MD5:
1a54e9230c500c5f49fd89af4b827900

SHA-1:
ace9506a7ec9ccfd8510b573184f0409725dd868

SHA-256:
4acbd3df2a319d08a32a95faee428f447c85e0e125651452371d516535eef1fb

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 1:16:02 AM UTC  (today)

File size:
202.1 MB (211,927,944 bytes)

Product version:
1, 0, 0, 0

Copyright:
NVIDIA Corporation

Original file name:
7ZSfxNew.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\301.42-desktop-win7-winvista-64bit-international-whql.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/2/2011 2:00:00 AM

Valid to:
9/2/2014 1:59:59 AM

Subject:
CN=NVIDIA Corporation, OU=Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=NVIDIA Corporation, L=Santa Clara, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
43BB437D609866286DD839E1D00309F5

File PE Metadata
Compilation timestamp:
7/23/2007 2:35:27 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3145728:1Xl87WVEAiO8cniB3d/Lifk919I5Z2QKQaARzsid7nUd12C79Z3mhYYhigcncU+X:1XlrCN1tzAiQXhRYm+2CDmhY9ideJ6

Entry address:
0x11DE6

Entry point:
55, 8B, EC, 6A, FF, 68, E0, 49, 41, 00, 68, E0, 1D, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 28, 41, 41, 00, 59, 83, 0D, 64, 97, 41, 00, FF, 83, 0D, 68, 97, 41, 00, FF, FF, 15, 2C, 41, 41, 00, 8B, 0D, 40, 93, 41, 00, 89, 08, FF, 15, 30, 41, 41, 00, 8B, 0D, 3C, 93, 41, 00, 89, 08, A1, 34, 41, 41, 00, 8B, 00, A3, 60, 97, 41, 00, E8, 1C, 01, 00, 00, 39, 1D, 90, 91, 41, 00, 75, 0C, 68, 6E, 1F, 41, 00, FF, 15, 38, 41...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
73 KB (74,752 bytes)

The file 301.42-desktop-win7-winvista-64bit-international-whql.exe has been discovered within the following programs.

iTunes  by Apple Inc.
Apple's iTunes is a proprietary media player computer program, used for playing and organizing digital music and video files on desktop computers. It can also manage contents on iPod, iPhone and iPad.
www.apple.com/itunes
9% remove it
LAME is a library that allows some programs to encode MP3 files. LAME is free, but in some countries you may need to pay a license fee in order to legally encode MP3 files.
9% remove it
SketchUp 8  by Trimble Navigation Limited
Publisher's description - “Redecorate your living room. Invent a new piece of furniture. Model your city for Google Earth. There's no limit to what you can create with SketchUp.”
www.sketchup.com/intl/en/product/gsu.html
9% remove it
 
Powered by Should I Remove It?

The file 301.42-desktop-win7-winvista-64bit-international-whql.exe has been seen being distributed by the following 13 URLs.

http://kr.download.nvidia.com/Windows/.../301.42-desktop-win7-winvista-64bit-international-whql.exe

http://ru.nodevice.com/download_file.html

http://de.download.nvidia.com/Windows/.../301.42-desktop-win7-winvista-64bit-international-whql.exe

http://de.nodevice.com/download_file.html