driverupdater.exe

Energizer Softech Pvt ltd

The application driverupdater.exe by Energizer Softech Pvt ltd has been detected as a potentially unwanted program by 4 anti-malware scanners.
Publisher:
Energizer Softech Pvt ltd  (signed and verified)

MD5:
5e98410b234b4715beeaf771cf2fcab3

SHA-1:
1ba2959d63d44504144aaac5e39b4a39f4ed3177

SHA-256:
5213bac6c999d4572debde34c96e3cbd685a81d8cd539b4951cb877aef87c65d

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 12:04:36 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAdware
1.3.0.6379

Reason Heuristics
Win32.Generic.EnergizerSoftechPvt.Meta
15.7.21.18

Sophos
Energizer Softech Installer
4.98

Trend Micro House Call
Suspicious_GEN.F47V0525
7.2.202

File size:
1.8 MB (1,922,600 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\driverbooster\driverupdater.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/20/2011 8:00:00 PM

Valid to:
7/20/2016 7:59:59 PM

Subject:
CN=Energizer Softech Pvt ltd, O=Energizer Softech Pvt ltd, STREET=13/267 Geeta Colony, L=Delhi, S=Delhi, PostalCode=110031, C=IN

Issuer:
CN=COMODO Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
209A749E9EB13B3BCA0002A965947A5D

File PE Metadata
Compilation timestamp:
3/31/2015 11:47:42 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:vttY/f4G3TY4YiTiV/Gf9njCInIgCG1Vd3rAlbbuHxhYnnLiIoJJuEr:FcfhTY41u/GfwoXkfuHxOLjo/uEr

Entry address:
0xBD906

Entry point:
E8, EC, C3, 00, 00, E9, 7F, FE, FF, FF, 8B, 44, 24, 0C, 53, 85, C0, 74, 52, 8B, 54, 24, 08, 33, DB, 8A, 5C, 24, 0C, F7, C2, 03, 00, 00, 00, 74, 16, 8A, 0A, 83, C2, 01, 32, CB, 74, 72, 83, E8, 01, 74, 32, F7, C2, 03, 00, 00, 00, 75, EA, 83, E8, 04, 72, 12, 57, 8B, FB, C1, E3, 08, 03, DF, 8B, FB, C1, E3, 10, 03, DF, EB, 1B, 5F, 83, C0, 04, 74, 0E, 8A, 0A, 83, C2, 01, 32, CB, 74, 40, 83, E8, 01, 75, F2, 5B, C3, 83, E8, 04, 72, E5, 8B, 0A, 33, CB, BF, FF, FE, FE, 7E, 03, F9, 83, F1, FF, 33, CF, 83, C2, 04, 81...
 
[+]

Entropy:
6.4876

Code size:
1.2 MB (1,262,080 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to one2.preventon.net  (87.106.189.113:80)

TCP (HTTP):
Connects to ec2-52-3-64-241.compute-1.amazonaws.com  (52.3.64.241:80)

Remove driverupdater.exe - Powered by Reason Core Security