DriverTuner.exe

DriverTuner

LionSea Software co., ltd

The application DriverTuner.exe by LionSea Software co., ltd has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DriverTuner’. This file is typically installed with the program DriverTuner 3.5.0.1 by LionSea SoftWare. While running, it connects to the Internet address 52.39.c0ad.ip4.static.sl-reverse.com on port 80 using the HTTP protocol.
Publisher:
LionSea  (signed by LionSea Software co., ltd)

Product:
DriverTuner

Version:
3.5.0.0

MD5:
20b83455bec666c54562d46ce4e6d96e

SHA-1:
570464a8be15676848b1e588892b74ba27f8f7e9

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/22/2024 5:13:06 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.LionSeaSoftwarecoltd.L
14.6.4.18

File size:
10.1 MB (10,632,504 bytes)

Product version:
3.5.0.0

Copyright:
Copyright 2011

Original file name:
DriverTuner.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\drivertuner\drivertuner.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/21/2013 5:00:00 PM

Valid to:
3/23/2016 5:59:59 PM

Subject:
CN="LionSea Software co., ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="LionSea Software co., ltd", L=beijing, S=beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
288A6842C331C5443D747BDABF31E2A3

File PE Metadata
Compilation timestamp:
6/3/2014 3:58:37 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:vShBNKomnvVI/////////////////////g/////////////////////////////f:qKRHcyX1H8/lQjfOE9

Entry address:
0x6AC50

Entry point:
E8, 2E, 04, 00, 00, E9, 6B, FD, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 24, AA, 48, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 8B, FF, 55, 8B, EC, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, 68, 7C, A5, 46, 00, 68, 24, AA, 48, 00, E8, 5D, 04, 00, 00, 83, C4, 18, 5D, C3, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00...
 
[+]

Entropy:
6.0535

Code size:
455 KB (465,920 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DriverTuner

Command:
"C:\Program Files\drivertuner\drivertuner.exe" --boot


The file DriverTuner.exe has been discovered within the following program.

DriverTuner 3.5.0.1  by LionSea SoftWare
www.DriverTuner.com
48% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to google-public-dns-b.google.com  (8.8.4.4:80)

TCP (HTTP):
Connects to 52.39.c0ad.ip4.static.sl-reverse.com  (173.192.57.82:80)

Remove DriverTuner.exe - Powered by Reason Core Security