driverwhiz.exe

Driver Whiz

383 Media, Inc.

The application driverwhiz.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from download.driverwhiz.com.
Publisher:
383 Media, Inc.

Product:
Driver Whiz

Version:
2.6.2

MD5:
5126cdf5c32dc40e8f289113fd0d0273

SHA-1:
c70f3ce9553dcd56ac92deaa4bd976d136d15f18

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 6:53:36 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.383Media.Installer
16.7.4.3

File size:
9 MB (9,443,184 bytes)

Product version:
2.6.2

Copyright:
Copyright (c) 2013 383 Media, Inc.

Trademarks:
Copyright (c) 2013 383 Media, Inc.

Original file name:
DriverWhizSetup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\documents and settings\cbjgm\meus documentos\downloads\driverwhiz.exe

File PE Metadata
Compilation timestamp:
12/25/2013 3:01:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:61MmQqQWes1Igm4of47EBE7C00qvw7Rcpew+4VRA8iGF///Zx:61M/DWS7f2O4o7Rc64bA8iGFH/z

Entry address:
0x3219

Entry point:
34, D0, F7, C7, 12, F9, A1, 6B, 0F, B7, DE, 8D, 0D, 19, 59, F9, 4D, 88, C9, 0F, BE, D1, 13, F5, 0F, AF, FF, 3C, CD, 0F, AF, E9, 85, CF, F3, 33, C9, 87, D6, 76, 03, C6, C2, E1, 68, 10, E7, 85, 00, 68, 6A, 65, 44, 00, 08, EA, F7, C0, CE, AD, CB, D4, 4B, 83, E5, 00, F7, C2, 3E, 4F, 73, 5A, 8D, 35, 96, 27, 7D, 37, 87, F7, C6, C3, 22, 2A, C2, F2, C7, C6, D6, FC, F3, 65, 81, C5, 4A, 01, 00, 00, 8D, 1D, 7D, 8F, E7, 8E, 81, ED, 49, 01, 00, 00, 84, DF, 80, F8, E0, 89, F3, EB, 07, 47, 80, D3, CD, 0F, BF, CD, 47, 32...
 
[+]

Code size:
23 KB (23,552 bytes)

The file driverwhiz.exe has been seen being distributed by the following URL.

Remove driverwhiz.exe - Powered by Reason Core Security