requestdriver_whiz_2.exe

Astalavista

The application requestdriver_whiz_2.exe has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from softnewready.searchfornewads.com.
Publisher:
Astalavista

Description:
Download Manager

Version:
1.1.6.5

MD5:
921860841207b7936fce75c1121f338f

SHA-1:
a4a0100bc66ed9dd2c49a9e68d18266a7c49c7ed

SHA-256:
cc9eaffb28abef84775a732e2a1aa0e3229f360bf769bd1e7160848a463a0ebb

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/27/2024 9:31:35 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
160119-0

Dr.Web
Trojan.InstallCore.1457
9.0.1.05190

Reason Heuristics
PUP.Bundler
16.2.2.11

File size:
104.1 KB (106,624 bytes)

Product version:
1.1.6.5

Copyright:
Copyright © 2015

Original file name:
PreInstaller.NET.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
1/28/2016 3:39:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
48.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:haxo1MNIkQE8QCrGpxqKRPI/g5o4s9kBTUbpxcKo4qWQlv:hmNw3QQGRe4s9kxUVaKo4qWQlv

Entry address:
0x17E7E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
88 KB (90,112 bytes)

The file requestdriver_whiz_2.exe has been seen being distributed by the following URL.

Remove requestdriver_whiz_2.exe - Powered by Reason Core Security