drivers.exe

Build Input

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application drivers.exe, “Premium Installer ” by Build Input has been detected as adware by 30 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
Premium Installer   (signed by Build Input)

Product:
Premium Installer

Description:
Premium Installer

Version:
2.4.8.1

MD5:
43f3e6fce9d5b766393cdf34d45538b1

SHA-1:
43efbe1c0a839ba661d38c9eec082664c4f425e4

SHA-256:
3d43d4b086770f3e969cf9d76e3b5e551f061bff4b25d91d6b2866c7276714f9

Scanner detections:
30 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 1:13:18 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.25
6762526

Agnitum Outpost
PUA.iBryte
7.1.1

AhnLab V3 Security
2015.03.06

Avira AntiVirus
Adware/iBryte.bxoy
7.11.214.38

avast!
Win32:IBryte-KK [PUP]
150129-1

AVG
Adware AdPlugin.ABH
2014.0.4257

Bitdefender
Gen:Variant.Application.Bundler.25
1.0.20.325

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.AgentCV.HWYE
21309

Dr.Web
Trojan.DownLoader11.30626
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.25
9.0.0.4799

ESET NOD32
Win32/AdWare.iBryte.BG application
7.0.302.0

F-Prot
W32/A-512ed8f8
v6.4.7.1.166

F-Secure
Riskware.Gen:Variant.Application.Bundler
5.13.68

G Data
Gen:Variant.Application.Bundler.25
15.3.25

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.200.15178

Kaspersky
not-a-virus:AdWare.Win32.iBryte
15.0.0.543

Malwarebytes
PUP.Optional.OptimunInstaller
v2015.03.06.02

MicroWorld eScan
Gen:Variant.Application.Bundler.25
16.0.0.195

NANO AntiVirus
Riskware.Win32.IBryte.dehlnk
0.30.0.296

Norman
Gen:Variant.Application.Bundler.25
03.12.2014 13:20:04

nProtect
Trojan-Clicker/W32.iBryte.125816
15.03.05.01

Quick Heal
TrojanDownloader.Badur.A5
3.15.14.00

Reason Heuristics
PUP.Bundler.Adknowledge
15.3.6.2

Sophos
PUA 'iBryte Optimum Installer'
5.11

Vba32 AntiVirus
3.12.26.3

VIPRE Antivirus
Threat.4798837
37788

Zillya! Antivirus
Adware.iBryte.Win32.1601
2.0.0.2089

File size:
122.9 KB (125,816 bytes)

Product version:
2.4.8.1

Copyright:
Copyright (C) Premium Installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
English (United States)

Common path:
C:\users\{user}\downloads\endeavor\endeavor photos\drivers.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/23/2014 8:00:00 PM

Valid to:
3/24/2015 7:59:59 PM

Subject:
CN=Build Input, O=Build Input, STREET="4600 Madison Ave, 10th FL", L=Kansas City, S=Missouri, PostalCode=64112, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0093C151407610A7B56F799C03CB8D955D

File PE Metadata
Compilation timestamp:
8/27/2014 9:15:13 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:FcxLmb03AbuOdpPkMKee/ipWVUe5XXJ1qDrIPSkTCmXqqeyYaZLaTZ:mdmb03SuOdmMXrIakTCmcaAZ

Entry address:
0x62F5

Entry point:
E8, 3E, 05, 00, 00, E9, 36, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, F8, B1, 40, 00, 89, 0D, F4, B1, 40, 00, 89, 15, F0, B1, 40, 00, 89, 1D, EC, B1, 40, 00, 89, 35, E8, B1, 40, 00, 89, 3D, E4, B1, 40, 00, 66, 8C, 15, 10, B2, 40, 00, 66, 8C, 0D, 04, B2, 40, 00, 66, 8C, 1D, E0, B1, 40, 00, 66, 8C, 05, DC, B1, 40, 00, 66, 8C, 25, D8, B1, 40, 00, 66, 8C, 2D, D4, B1, 40, 00, 9C, 8F, 05, 08, B2, 40, 00, 8B, 45, 00, A3, FC, B1, 40, 00, 8B, 45, 04, A3, 00, B2, 40, 00, 8D, 45, 08, A3, 0C, B2, 40...
 
[+]

Entropy:
5.9918

Code size:
25 KB (25,600 bytes)

Remove drivers.exe - Powered by Reason Core Security