driver.exe

ВERSHNET LLC

The application driver.exe by ВERSHNET has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from games-port1.ru.
Publisher:
ВERSHNET LLC  (signed and verified)

Version:
1.0.0.0

MD5:
7cdd8134eb2167c1524f0383b4165e73

SHA-1:
cdded7fae5bed9a3adf1f29d3c859650ab620e8e

SHA-256:
57e72a9755a49f93289d5736372bb599637a02c1d1168d48c2ee2c07f2e4ae3a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/23/2024 11:38:37 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OutBrowse.ERSHNET (M)
16.3.12.15

File size:
4.3 MB (4,502,824 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\driver.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/5/2015 2:00:00 AM

Valid to:
2/6/2016 1:59:59 AM

Subject:
CN=ВERSHNET LLC, O=ВERSHNET LLC, STREET="600-Richchya, house 66, office 10", L=Vinnitsa, S=Vinnitskiy Region, PostalCode=21027, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0DCBDEF5E756334284571793EA14D465

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:5NZC0lqzykyMGXRMl2yE+rFwkDaZDGH8efx05pViOFqLn9aeHv7KicFaHQJYQv46:5PC0lSyJhMl2IpGZDW8Mx05//Yn9aePk

Entry address:
0x1EAA4B0

Entry point:
60, BE, 00, 10, EE, 01, 8D, BE, 00, 00, 52, FE, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
3.8 MB (3,973,120 bytes)

The file driver.exe has been seen being distributed by the following URL.

Remove driver.exe - Powered by Reason Core Security