revosetup.exe

Revo Uninstaller Setup

VS Revo Group

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.tamindir.com and multiple other hosts.
Publisher:
VS Revo Group Ltd.  (signed by VS Revo Group)

Product:
Revo Uninstaller Setup

Version:
1.9.5.0

MD5:
4f99cae27ffd46712e65c21444aacdfc

SHA-1:
7fc81fb6cee0ba858b3801162c231a5f43c94a02

SHA-256:
31a8126c990a2bc73cc772d4a2194b43bba03e14e770c5dbb72f2cd12f179703

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/24/2024 11:50:58 AM UTC  (today)

File size:
2.5 MB (2,623,656 bytes)

Copyright:
Copyright VS Revo Group

Trademarks:
Revo Uninstaller is a trademark of VS Revo Group

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\revosetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/19/2010 7:00:00 PM

Valid to:
12/18/2013 6:59:59 PM

Subject:
CN=VS Revo Group, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=VS Revo Group, L=Ruse, S=Ruse, C=BG

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
017BF223028469B14729A770A1F0EA2D

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:sKj1BodkgV5aaBS8lY72jt36SOHmQtggHwWmlZ0/Hv:s+BCvJSY6SOvaMY4v

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9922

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file revosetup.exe has been discovered within the following programs.

Steam  by Valve Corporation
Steam is a digital distribution, digital rights management, multiplayer and communications platform developed by Valve Corporation.
www.steampowered.com
10% remove it
WinZip 19.5  by WinZip Computing, S.L.
www.winzip.com/wzgate.cgi?lang=EN&url=www.winzip.com
About 6% of users remove it
 
Powered by Should I Remove It?

The file revosetup.exe has been seen being distributed by the following 50 URLs.

http://www.tamindir.com/indir/MjAxNy0wMS0xNiAyMDo1ODo1Ng==/revo-uninstaller/windows/.../

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_es&type=PROGRAM&Expires=1426121417&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=O3cNajvbxqBSbUfIvmuHTDwzHpmO1ss4VuQ8rnWDqS7OXVtyahj4~u0vBu9aHMavKZ-wFEEq80SyW9GXVhsvxYx3CksK59lbhTMan7PCidTOYBtz86jl6ilf2-x68xfb2RSVjQdajHhrUKfEzeI7aezanwh~VBxwuQDgog8nAWw_&filename=revosetup.exe

http://cdn.mysoftspace.net/?s=4Fhd00xsQtsb_oqCVf2kDg&pf=Revo_Uninstaller_Rus_Setup.exe&pt=Revo Uninstaller ??? Windows&src=softcatalog.info

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_es&type=PROGRAM&Expires=1476514401&Signature=bLYdXNKeiTO~pJ-lOXMT~mKxUf0arq~DakgoE0ZiA6PY3sV0tQ1092ZsiIOYNonnkRjfa7ghsaC0oiDBszWxl69i5Xe180woChuYq3hMKoeNA9rHLIxPR03j3-wFT0oqKFg7bj7KJvSDJtS~MHH56xpVpugbZzoqNDNz~4vAL~A_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_br&type=PROGRAM&Expires=1480635752&Signature=b9SfolkawPnDtfXHx1-CgJNIP0H1ByjOI7FoUoICQf0TwO5zfXGQK5Zidgmk5cyRmjgm5Fx6q2cHYJiwlanzmLcPEt1j4WnjuhhbNAnnpNyEdfXlaX~SFIrgVZheWbJpWbd-cPncQosLn9EPkHLhldUCdeKjcMkqkHUMMXBBcoM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_br&type=PROGRAM&Expires=1443328513&Signature=ALkj3bhON73SEhTkcGwn-5Bnp7XUu1t3BqwvlOKXsXy1ANjvKc8vG6Fz0mfbsrQPW3kYQ39JP0OFMaQExZl8pBLogKBbwOa75Ka~Q2XQQRUEP8ySPO48gBBuDU0BdJ06rmJucYudnYxq2M9emqjQ1tQbmbEQTJ3fiLi3WGWWijs_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_it&type=PROGRAM&Expires=1475959600&Signature=TJ781VfzEsMTYPaE9m5WtMShgW~DLF-lvJ~YPTk1Z9eI8lYSlfSINYiPN7v~Tc77GAkIgpBA0QO8p9-S8Gg7cUE-VMoBFsVFIbcSJMUxIV9YE87aHPCbZ86hwIfUWvYltdm0oujfAGxe9w9q1Tjc1VPLCzVn7aEQPX~Hrl7XYnE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_it&type=PROGRAM&Expires=1465249558&Signature=ZGqs70Bo4A6sCNiy106c7Q6OGc5RfqdKYZBDVRsmxdFLJGBTe0OwF2eYgle-1vog5vM7C7NToekMVQqNk4Dp8lAT890dlfxUW0iIadx3QhdhxCBYiNXzQuwR1fNcZPl~AuaY0S0I2wZ5YkqJSBMAV92K~gzkHJszl340wCnFBcU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://lb.cdn.m6web.fr/d/c/a/c1fe7117d8e0c9a64c318e72929a1940/578b932b/soft/.../revouninstaller_1-95_fr_39528.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_es&type=PROGRAM&Expires=1444039514&Signature=OS~xgUyWKUyi3RcJayrPFX6D~pShhxLRoWSMIqjAb3r-hRrlCm1-xK3D9CwSDVqa5B32US7k68GU5O2BE0qsUh0hSsDgu9G8UcwDcPYS9NsCKYRweI13F-~QnRr2DgU9l2hGzOzc2xQeLsnhw5xNwhgh9KswrRH6Ob7ElEuuxwI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_br&type=PROGRAM&Expires=1485426317&Signature=IQ0LQC4wLZns-sbURocqywBbE2QdSDVagVFaws8JF-dbOMSGjqUqVduF68pzsza9r8VS69xPSYEgsbgnXzYbafa8pEh8MzSxsEZiCQahTP8GhioiYioOMWCUX-mpR5GUYn~0HLxl0SXAV8SLD0dP-5ibJXM~XN7Fm7Nz0XeHd1A_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_br&type=PROGRAM&Expires=1475848160&Signature=WjJqa-7Hox0u8K-9B80OWfvKMEz7Yf5k~dwkD5rdhNRholN9gUz3WqJZmZHf~KXSdiq8VhLgraNE1yW1Uz7leG1ywxAC78qKckUwPr47LUyRXW2CabVaZXabaSZ3rx5Qf0CW~JBCUP2zkmcpvfVumfV6WCnP9J0fxgIxx232qt0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://softvisia.com/request.php?mirror.1067.11

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_es&type=PROGRAM&Expires=1479291149&Signature=aWu8wydPjZ9oJSgH3hM~MULJO6sVrbmzmfBToPWWAqmF-lqE1OA8QPx-pYMkldErry6mQIt24~KA0lWDPkSkpLbgYZXpUZVvzRmA2YVeUmkrGIqjmq~NBuFEdPA1OY4qc9yrZcclLGGROYCsIJyWOP-6NFo9lBKCjtKNFyTdWoo_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_fr&type=PROGRAM&Expires=1482974703&Signature=I6OV5mbDKOHK3~eV4TaZzt~NdDQMDHNK4jpawQ-8kg5heO1Me4S53qw4IYln9XssZhKUP~vNNOOXwtEgleDQdiH17~JBgT~-dQmve8rAK1NBF30eY3OSMXwiOe0tX-ev~8dqUe5L7ATJPkLAe81h1Hbn7Wi2T~-03U2SZKU1EyY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

https://dw.uptodown.com/dwn/boSs-FQyOSazuvLeoRMyxXhgnyhNAoHarKulvQmb1qUMu2s54-o4pf6F_dOqXSu3vOuvucd2BE_-iQhY740ibls2dYRpf12AblPQckQV046UYnA5tlRHzJ4lLx7-u-30/JaRQGLNVdalmr0ZXVqMqUpBdQ0_hzvHjSL5cBk2_KpDRwVEuXZKquuvmD_fKOCebf6Ja-pB8uO5pG-ov33mBhKt9P08E_eW_P7UXreGZJd49kUNZrG8k1ttd18yUzQ5v/dKLQFc_aqq8rPk8dKKDqsi49BEcwTEAGZ67Mqg3HWdV6EpBXaF56nJDngeh-_9wcRKyZQdyBbs0ahkwlqVVX1pid0pOhci-yehHDvJQ_nlajEpxUAvvAiCJ56twEsVSr/.../

http://indir.gezginler.net/i/5591/.../

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_it&type=PROGRAM&Expires=1454191373&Signature=I4ZyF~Hjv72gnFicmwcQbYeLnpG8sv1nYpLFDAnbj~erQ1erGvVZjsai03HPUNrNpEe9Rvd45DQ2rkxldRBNzNXci28d6xhO0efQx5xlA27q67rAS06n7-3lWj3niJJEME9TGZlpy~h8DBtm5Q79KbefbLKElvxRDeGlJe6veHU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_fr&type=PROGRAM&Expires=1484274435&Signature=Bc1-ejh47C~Soa45ZJS~53JWnxEOdf6n2g0Mrp1xm3M~BDOSs1gUrMl3VdHwReOwsNhCufI8UteOibl7S-jx1RaztZjdpqrl808SJup1Yd3bp~3G4kEYA2Tfqkjtf2ElJnb2wN0gIFFSovdrSK~~mfvPZ7rLaFJ1EG4UPlgwX4M_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_en&type=PROGRAM&Expires=1454029354&Signature=bEgbt1Ofv0FxHLnQca-uJwgi7tjOoGludVLnrWkwPfs4Ukzze1bz9gr3D5dq4dG~rVfTpTiO1-c2QDHOd0RwUBiYsJbSG7mFGZ9X3bXQ1XtIKPXMeJMEnp~6Gn4johkILDnuIQhZyU3vxVuZDa8axZiM3y1ByiRaN39u9Rngg3M_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_es&type=PROGRAM&Expires=1483787917&Signature=ZSfwFCp5~6TXjOk2o7ecnAuAtE1UXBQXkbygV8holkrLakDdRAAyD22PYe09FQXTSg2uRV3whEazmNBNvgmasJ4J4ezL8cw7xM-yvY5QIgb6hrysLs7JguHC11VrBVvQC1cIFxDTmHgxKpySEqXy8QSwahMzBlPoEJsPKG9p6ZQ_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_it&type=PROGRAM&Expires=1463813996&Signature=c4nEJI5TyOM4TLsGYtMVshtf4BI8YzMCpBEufBrNLzyBFQCByDnDK2SyZf9f-VffTW2Z~uPz61wY7SmQEJJ606apkXPp4gTiVcMF9hEMGtqX39db6BnLbYs3LQ3tKap3ahFV4QeqKA8uI-JUaLFdSvNhbjg3dsubl4UZOQmSH-c_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_es&type=PROGRAM&Expires=1434012612&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=WtuwYsARZ1ZCTe-KbIfagxqXGnltiUAvhU7tp27fKsp3pGEPuMhH22YhK9IioJaz~rj-kSl5GynZA0siIhaT3mz6OlR1hUnhClQvSUw6~H0eHVNPeHfb9YbE6gR3r180dt9Ij6LL8NHdKL9LN0xw3HhEVq6cvv3koSH5QEUIdf4_&filename=revosetup.exe

http://www.tamindir.com/indir/MjAxNi0wOS0xOSAxMjo0Mzo1OA==/revo-uninstaller/windows/.../

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_en&type=PROGRAM&Expires=1454031795&Signature=SYzYos346HVMlQauJalLeFsWEhTFFDNf6SFIJexCMYHNn~1iNHGj8VDz6072jTUHztGasrO1YwRfYdZ631yvrAE3xDLJbwndzTH8Z-sYVQxZRFZjNJpTS5ekrgjeHn-uMzYaoVqRrjOBtLKCtw0YAgiImQN6XXncM84dBIuZAk4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_es&type=PROGRAM&Expires=1437667921&Signature=ECOhuNfv3uRM2g3-vZppFysMjmfAcGOdOEW8vcJkvI4XB0LQGyHRgmJxyf9RIF84bC-x6zDRHaiZSb0Rpew7eyQ4W6z7N69IwqH3cfec6EsrI3veQIdm~wZfBIz9Sy5Y2ZGE2htIRa606XyR4WKp7uhfnLwCDIGbsrzn21AG83E_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_br&type=PROGRAM&Expires=1480461493&Signature=XWzbav3AgqT0qvvhqimbWvwrA-BEdqarJwN7ibttIfWrHXHQ445RB62SlMB0Biuhg4wn9WNFw2X6QhuSZ3DG-4IB9xeRntbxO9Vcs0AtMMSeMoVq3Ct9z-JZGccfG8smwDojeqE2iPHt0E8o3p6ZpIFgthfG9KyA8L0BhoR5oIA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_br&type=PROGRAM&Expires=1488007830&Signature=eNaPoa5zYhiCDppGvyIUo4OXU~cpvTCTYvUfiQ0oFGU4UI1Wl5Y36-aZdQ7n~JQ5QUrHLZf4~UDsnEZiWH2epIHqqCv0G0RRUqXf3tSHy-sCek~Xbuy-zqWcyhKiqYxloUTVFttnrB7VMeWKvx361NfxgrL52mVMuAPGiM0IhBg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_en&type=PROGRAM&Expires=1485585273&Signature=VYrkF9ldLtkpFF5boje0S9YyMkYmqch--VcbphGk5RYhkyAnUrzI5cv0TRvkmIQc-j20hX13kFk9rluW9KzXKsvi7Ir0rJyGkv5PkoqY-AWpa1dG4Rw4sZWXWYKgsD2d~ZI-hhcCg7ZFjh9P0UsOcR1vuNzl4zmHXH~3n5l0pvE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=revosetup.exe

http://gsf-cf.softonic.com/7fc/81f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=62963&instance=softonic_es&type=PROGRAM&Expires=1431503755&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=VBYSJlLUXoHUYt~w6tk6pJHr1Cgiynq1oIVjBuGvLNfc28K4Rdn7v9tavt1dDCnM0E1HKsT440vIclyraIZZMt2-e4tP4lTN3cFRBPA6gKA2IvYTxibxNQt2j39qYpxwvSMwatcg34AS3XGJZ60L4IQsDrWX2imKqVERvHjZKhs_&filename=revosetup.exe

Latest 30 of 942 download URLs

Scan revosetup.exe - Powered by Reason Core Security