DriverDetective.exe

Driver Detective

PC Drivers HeadQuarters LP

The executable DriverDetective.exe has been detected as malware by 8 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from RevenueWire's affiliate distribution platform uyc.pcdriversheadqu.revenuewire.net.
Publisher:
PC Drivers HeadQuarters LP

Product:
Driver Detective

Version:
10.1.2.51

MD5:
d23bc9c7e82c429943fd4c817a13dc4c

SHA-1:
cb8c5d7c65cfee021d80dfc982f08630df7fe9a6

SHA-256:
26b7fa6f32173f555fa700861982369bee02ab73dfa2eaae3b1c1a223f6c7c6b

Scanner detections:
8 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/5/2024 3:19:55 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160708-3

AVG
Win32/Sality
2015.0.4604

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.225.1693.0

Norman
Win32.Sality.3
28.05.2016 15:32:18

File size:
405.6 KB (415,360 bytes)

Product version:
10.1.2.51

Copyright:
PC Drivers HeadQuarters LP

Original file name:
DriverDetective.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\driverdetective.exe

File PE Metadata
Compilation timestamp:
10/7/2014 12:40:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:uA18BZyrfMVuJOobUNoUox/uZcCGreyHFvFLTW5Q65QTcAKTwygaoD1DmOZgsMP:/DDQMbUOvCEhNFLTuDOKTwfatOZLMP

Entry address:
0x3217

Entry point:
1A, D4, 87, C5, 38, FF, 69, C8, 0D, 69, 4A, 6C, B8, 8C, 13, 00, 00, 0F, CB, 05, D2, 0E, 00, 00, 4B, 2B, D0, EB, 06, 69, C0, 22, E5, A8, 8D, 81, EA, 60, 05, 00, 00, B9, 4B, 5B, 25, 9E, C7, C7, F9, 1D, 11, 26, 8B, CD, E8, 32, 00, 00, 00, 81, FD, E6, 32, 00, 00, 77, 03, C6, C6, 40, 0F, BF, D2, 47, 70, 02, FF, C1, 53, 75, 0A, BD, 93, E4, 80, 18, 0F, AF, CB, B3, CD, 5D, 49, 8D, 35, CD, 24, D3, 30, 8B, D5, 84, E4, 0F, B6, ED, 8B, C2, 4D, 5A, 87, DB, 69, F3, 32, 6F, 2D, 3E, 8B, C0, 85, C9, 0F, 6E, DA, 71, 02, FE...
 
[+]

Entropy:
7.8446  (probably packed)

Code size:
23 KB (23,552 bytes)

The file DriverDetective.exe has been seen being distributed by the following URL.

Remove DriverDetective.exe - Powered by Reason Core Security