setevoy-drayver-dlya-windows-7-64-bit-noutbuk-hp-pavilion-dmos.exe

The executable setevoy-drayver-dlya-windows-7-64-bit-noutbuk-hp-pavilion-dmos.exe has been detected as malware by 6 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from use-savv.ru.
Version:
1.6.2.9

MD5:
8128964a4c7b188126949cb68d3679af

SHA-1:
fb024402b8d6519b9cfca5cab27f4bf01e2aa0f4

SHA-256:
603f9aec81214d7652eb3d9ccbfa24021956e8e7c86373345e6d746ee177a0b3

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
2/25/2025 7:52:11 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160518-2

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.225.469.0

VIPRE Antivirus
Threat.4721115
29708

File size:
4.9 MB (5,128,184 bytes)

Product version:
1.6.2.9

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
9/27/2011 12:14:30 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:m8oFdYrqbFhzkp2nLWZlsanrejZWH74aMgb+Gv2/fd:m7FdaqbzzkSLMnS074aMgb+Gs

Entry address:
0x4125F6

Entry point:
8D, 35, CC, 71, 07, 26, 39, D6, 4F, 80, D7, 35, BF, 08, FD, 86, 9D, 3B, C6, 74, 05, F6, C6, F0, 89, EB, BA, 00, 00, 00, 00, 84, FC, 86, E0, 0F, B7, C3, 85, F1, 76, 04, 86, C3, 28, D1, 4F, 81, C2, D3, C6, 0F, 00, 2B, F0, 8A, D9, 81, EA, D2, C6, 0F, 00, 31, CF, FF, CD, 69, F8, 48, 96, 16, E6, 80, E8, E4, 81, FA, B0, 06, 00, 00, 0F, 8C, C7, FF, FF, FF, F3, 89, FD, 89, E8, E8, 00, 00, 00, 00, 5A, 08, C0, 84, D2, 84, C8, 0F, AF, EB, 89, EE, F6, C6, E3, BB, 00, 00, 00, 00, B1, 63, 45, 0F, AF, E8, 3C, 2B, 3D, 84...
 
[+]

Code size:
4.1 MB (4,282,880 bytes)

The file setevoy-drayver-dlya-windows-7-64-bit-noutbuk-hp-pavilion-dmos.exe has been seen being distributed by the following URL.