DriverGenius.exe

Driver Genius

Driver-Soft Inc.

The executable DriverGenius.exe has been detected as malware by 3 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. While running, it connects to the Internet address f8.a9.e443.ip4.static.sl-reverse.com on port 80 using the HTTP protocol.
Publisher:
Driver-Soft Inc.

Product:
Driver Genius

Version:
17.00.0137

MD5:
3817e16b801513fcdf62318636806c05

SHA-1:
a6998f9bd2b9a992c70736ab9c5fa736ebad2f01

SHA-256:
88837349e04d9dcca921876d9d2ea82e4ec1f96447f600ce56d3d8c8cea57095

Scanner detections:
3 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/25/2024 3:03:32 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.16.24

File size:
4.5 MB (4,709,647 bytes)

Product version:
17.00.0137

Copyright:
Copyright (C) 2002-2017 Driver-Soft Inc. All rights reserved.

Original file name:
DriverGenius.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\driver-soft\drivergenius\drivergenius.exe

File PE Metadata
Compilation timestamp:
1/21/2017 11:27:51 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1000

Entry point:
E9, 63, 28, 06, 00, E8, 01, 00, 00, 00, C3, C3, F7, 1B, 9C, 53, 0E, 26, 56, 40, EA, E2, 8C, DA, 9D, 27, 11, AE, BA, 6E, 7B, 8F, 5B, E3, AE, AE, 35, AA, 42, 3A, 38, 50, 67, B2, E4, A8, 0A, 63, 18, 7A, 6C, 9D, 18, 26, 29, 0E, 6C, E7, A6, 79, 3C, CB, 24, A2, 33, 7C, C2, 1E, 66, 8F, 02, BC, AF, 2B, 3C, 1C, DC, 60, BB, EE, CF, 9A, B3, 57, EC, F2, 46, A9, 5D, 79, 20, B3, 16, 98, F5, 35, 88, 86, C6, BF, 93, 60, D2, 50, 9E, 8A, 45, 45, 5A, 98, 63, CD, B1, 1A, 63, A9, 7B, 26, 7B, DF, BE, 8E, 7A, AE, 3F, FB, 33, 74...
 
[+]

Entropy:
7.9956

Packer / compiler:
Xtreme-Protector v1.05

Code size:
1.9 MB (2,031,616 bytes)

Scheduled Task
Task name:
Driver Genius Scheduler

Trigger:
Logon (Runs on logon)


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to f8.a9.e443.ip4.static.sl-reverse.com  (67.228.169.248:80)

Remove DriverGenius.exe - Powered by Reason Core Security