driverrevolution-setup.exe

Операционная система Microsoft Windows

IT AUDIT AND COMPLIANCE SERVICES LLC

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable driverrevolution-setup.exe, “Исполняемый файл для игры "Червы"” has been detected as malware by 1 anti-virus scanner. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software.
Publisher:
Microsoft Corporation  (signed by IT AUDIT AND COMPLIANCE SERVICES LLC)

Product:
Операционная система Microsoft® Windows®

Description:
Исполняемый файл для игры "Червы"

Version:
6.1.7600.16385 (win7_rtm.090713-1255)

MD5:
2e6ec6356a433fa7f182629244567173

SHA-1:
99dcdda292bc164ab9b473ca85bd853ac89877ac

SHA-256:
a83a6d7da8b57673d9b182fc1ada2dac7a7bfa78927d01fbe7384e6ff89a563f

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/18/2024 3:24:19 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.12.17

File size:
265 KB (271,400 bytes)

Product version:
6.1.7600.16385

Copyright:
© Корпорация Майкрософт. Все права защищены.

Original file name:
hearts.exe.mui

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\driverrevolution-setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/10/2015 7:00:00 AM

Valid to:
11/10/2016 6:59:59 AM

Subject:
CN=IT AUDIT AND COMPLIANCE SERVICES LLC, OU=IT, O=IT AUDIT AND COMPLIANCE SERVICES LLC, STREET="vul. Vilyamsa Akademika, 6 D", L=Kiev, S=Kiev, PostalCode=03189, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00BB3CCAF99CC223A1AD34177B638A3BC8

File PE Metadata
Compilation timestamp:
6/24/2012 4:21:47 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

Entry address:
0x4120

Entry point:
55, 8B, EC, 81, EC, 0C, 02, 00, 00, C7, 85, 2C, FF, FF, FF, 00, 00, 00, 00, 8B, 85, 7C, FF, FF, FF, 89, 45, CC, 33, C9, 66, 89, 8D, 60, FE, FF, FF, 8B, 55, FC, 3B, 95, 50, FE, FF, FF, 75, 1F, 81, 7D, F4, C8, 33, 06, 00, 75, 16, C7, 85, 54, FE, FF, FF, 44, 04, 08, 00, C7, 85, 2C, FE, FF, FF, 00, 00, 00, 00, EB, 07, C7, 45, A4, 43, 16, 06, 00, 0F, B7, 85, 64, FE, FF, FF, 03, 85, CC, FE, FF, FF, 88, 85, DE, FE, FF, FF, C7, 85, 78, FF, FF, FF, 6F, CC, 02, 00, BA, 5C, 00, 09, 00, 8B, 8D, 7C, FF, FF, FF, D3, FA...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
35 KB (35,840 bytes)

Remove driverrevolution-setup.exe - Powered by Reason Core Security