driverreviversetup.exe

Driver Reviver

ReviverSoft

The application driverreviversetup.exe, “Driver Reviver installer” by ReviverSoft has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is typically installed with the program Driver Reviver by ReviverSoft LLC. The file has been seen being downloaded from downloads.reviversoft.com and multiple other hosts.
Publisher:
ReviverSoft LLC  (signed by ReviverSoft)

Product:
Driver Reviver

Description:
Driver Reviver installer

Version:
4.0.1.94

MD5:
b167b7fbe5526c8aa53028d35e0b7c56

SHA-1:
47e1bae5cfcc80bb186175753a6ead450a6733dd

SHA-256:
34f70768842efe14644f9fb60ae526382415bf14b83bfff4b48dc29dc14addf7

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 3:41:22 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ReviverSoft.Optional.Installer.Meta (L)
16.7.12.0

File size:
3.4 MB (3,607,720 bytes)

Product version:
4.0.1.94

Copyright:
ReviverSoft LLC

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\driverreviversetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/12/2011 4:00:00 AM

Valid to:
7/2/2014 3:59:59 AM

Subject:
CN=ReviverSoft, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ReviverSoft, L=Walnut Creek, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
67CBBBC287729969E701CBDA1DED7CA8

File PE Metadata
Compilation timestamp:
4/10/2010 4:19:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:94moPEw60bKtym59yKxcfucGDoNAqscSBh8xQP/Z9Cst2V9MaCOnSrOVhpE5lUjQ:9mPE90GtNGNAjWQ3M0MV7uOj1cPv

Entry address:
0x354B

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 84, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 98, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 86, 40, 00, FF, 15, 80, 81, 40, 00, 68, 04, 86, 40, 00, 68, A0, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file driverreviversetup.exe has been discovered within the following program.

Driver Reviver  by ReviverSoft LLC
Publisher's description - “Restore maximum performance and functionality to your PC's hardware and its components! Experts recommend Driver Reviver to keep your PC's Drivers up to date and restore optimum performance and functionality to your PC and its components.”
www.reviversoft.com/driver-reviver
43% remove it
 
Powered by Should I Remove It?

The file driverreviversetup.exe has been seen being distributed by the following 2 URLs.

Remove driverreviversetup.exe - Powered by Reason Core Security