driverrevolution-setup.exe

IT Proekt Invest, TOV

The application driverrevolution-setup.exe by IT Proekt Invest, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
IT Proekt Invest, TOV  (signed and verified)

Version:
2.0.0.7

MD5:
763c91cc34b243fca0dbb2d6afcecd86

SHA-1:
ccf446b45f923a96c52f751d4e17ea23c1e5e400

SHA-256:
a313189b7cbfa7ed4972b2322868e2ee06059732368d94997051dc393e3e72cb

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 5:30:34 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize (M)
17.2.20.3

File size:
5.7 MB (6,021,600 bytes)

Product version:
2.0.0.7

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\driverrevolution-setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/20/2016 3:00:00 AM

Valid to:
3/18/2017 2:59:59 AM

Subject:
CN="IT Proekt Invest, TOV", OU=IT, O="IT Proekt Invest, TOV", STREET="prosp. Vozzyednannya, 9", L=Kiev, S=Kiev, PostalCode=02160, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00BFE3D72E3FB3938D9D5EBA447C681BDA

File PE Metadata
Compilation timestamp:
2/12/2011 6:04:41 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

Entry address:
0x4DB000

Entry point:
55, 8B, EC, 81, EC, C4, 0B, 00, 00, B8, 6F, DF, 00, 00, 66, 89, 85, 14, FF, FF, FF, 0F, B6, 8D, 64, FF, FF, FF, 81, F9, D3, 78, 00, 00, 7D, 60, 8B, 95, 70, FF, FF, FF, 3B, 55, B8, 77, 55, C6, 85, 60, FF, FF, FF, 72, 8B, 45, 94, 05, 61, 40, 00, 00, 89, 45, F8, 0F, B7, 8D, C8, FE, FF, FF, 81, E9, 18, 35, 00, 00, 89, 4D, C4, 8B, 55, E0, 81, C2, FB, 51, 00, 00, 66, 89, 95, 64, FE, FF, FF, B8, 16, C9, 00, 00, 66, 89, 85, B0, FE, FF, FF, B9, 04, 9D, 00, 00, 66, 89, 8D, 84, FE, FF, FF, 33, D2, 66, 89, 95, 84, FE...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
5.2 MB (5,439,488 bytes)

Remove driverrevolution-setup.exe - Powered by Reason Core Security