PrivitizeVPN.exe

PrivitizeVPN

OOO

The application PrivitizeVPN.exe, “PrivitizeVPN Client” by OOO has been detected as adware by 7 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘PrivitizeVPN’. The file has been seen being downloaded from dl-web.dropbox.com.
Publisher:
OOO Industry  (signed by OOO )

Product:
PrivitizeVPN

Description:
PrivitizeVPN Client

Version:
1.0.0.1

MD5:
430739f114507dd2ea78d180a34ff9f3

SHA-1:
7c6198902e0bc567da6eced92ed461acf1f72688

SHA-256:
b3d5e6eafdc7c72254b1c898f8b9f452149bd6c1b938304cfbdded6c949450cf

Scanner detections:
7 / 68

Status:
Adware

Analysis date:
2/25/2025 4:51:58 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.Clod3af.Trojan
1.3.0.4613

Boost by Reason
Optional.Startup.OOO.M
188163

Dr.Web
Adware.Siggen.25462
9.0.1.0356

Reason Heuristics
PUP.Startup.OOO.M
14.3.2.16

Sophos
PrivitizeVPN
4.96

VIPRE Antivirus
Adware.Privitize
24554

XVirus List
Win.Detected
2.3.31

File size:
192.2 KB (196,784 bytes)

Product version:
1.0.0.1

Copyright:
Copyright 2012

Original file name:
PrivitizeVPN.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\privitizevpn\privitizevpn.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/2/2012 3:00:00 AM

Valid to:
8/3/2015 2:59:59 AM

Subject:
CN="OOO ""Industry""", O="OOO ""Industry""", STREET="Vsevolzhsky 2, bld. 2", L=Moscow, S=Moscow, PostalCode=119034, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D139BDA20096871840DCE08E6A80B6F0

File PE Metadata
Compilation timestamp:
9/10/2012 1:58:09 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:584VFCdzuTtG8QrIB+jYFWsTsGqcJMJKBFpD0vYB31UWeU:5/VFC5uTY+BKYQsTEcTigBJ

Entry address:
0x1356C

Entry point:
E8, 84, 6E, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8D, 42, FF, 5B, C3, 8D, A4, 24, 00, 00, 00, 00, 8D, 64, 24, 00, 33, C0, 8A, 44, 24, 08, 53, 8B, D8, C1, E0, 08, 8B, 54, 24, 08, F7, C2, 03, 00, 00, 00, 74, 15, 8A, 0A, 83, C2, 01, 3A, CB, 74, CF, 84, C9, 74, 51, F7, C2, 03, 00, 00, 00, 75, EB, 0B, D8, 57, 8B, C3, C1, E3, 10, 56, 0B, D8, 8B, 0A, BF, FF, FE, FE, 7E, 8B, C1, 8B, F7, 33, CB, 03, F0, 03, F9, 83, F1, FF, 83, F0, FF, 33, CF, 33, C6, 83, C2, 04, 81, E1, 00, 01, 01, 81...
 
[+]

Entropy:
6.4495

Code size:
128.5 KB (131,584 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PrivitizeVPN

Command:
C:\Program Files\privitizevpn\privitizevpn.exe \autorun


The file PrivitizeVPN.exe has been seen being distributed by the following URL.

Remove PrivitizeVPN.exe - Powered by Reason Core Security