driverwhiz.exe

Driver Whiz

Secure Installer Inc

This is part of the Air Installer, a download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application driverwhiz.exe by Secure Installer Inc has been detected as adware by 3 anti-malware scanners. The program is a setup application that uses the AirInstaller Download Manager installer. The file has been seen being downloaded from download.driverwhiz.com.
Publisher:
383 Media, Inc.  (signed by Secure Installer Inc)

Product:
Driver Whiz

Version:
2.5.3

MD5:
c3eee1cf6eddd72a0443640e09c228c2

SHA-1:
5be9982efd30f42bbe9d0d3aa0215ba8fa8c5561

SHA-256:
1835118259f8157e41236cc15c49c1d773d7fdbffbb63fc30b852273da059998

Scanner detections:
3 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 3:45:53 AM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Adware.Agent-59058
0.98/21511

Dr.Web
Program.Unwanted.796
9.0.1.0315

Reason Heuristics
PUP.Air Software.SecureInstaller.Installer (M)
15.11.11.1

File size:
7.7 MB (8,072,392 bytes)

Product version:
2.5.3

Copyright:
Copyright (c) 2013 383 Media, Inc.

Trademarks:
Copyright (c) 2013 383 Media, Inc.

Original file name:
DriverWhizSetup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
AirInstaller Download Manager (using Nullsoft Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\driverwhiz.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
11/5/2014 6:00:00 PM

Valid to:
11/6/2015 5:59:59 PM

Subject:
CN=Secure Installer Inc, O=Secure Installer Inc, L=Pleasanton, S=California, C=US, SERIALNUMBER=C3712890, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=California, OID.1.3.6.1.4.1.311.60.2.1.3=US

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA - G2, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
2D22C5F63B1EEA2D802C435A5D079FDE

File PE Metadata
Compilation timestamp:
12/24/2013 11:01:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:hG7GcvU1u70vjw7oi7o83o9oV4eQ2NMKbmqBa5:JZ1ugvjw7of83oG4eQiMKI5

Entry address:
0x3219

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 98, 37, 42, 00, E8, AD, 2D, 00, 00, A3, E4, 36, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, A0, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, E4, 91, 40, 00, 68, E0, 2E, 42, 00, E8, 57, 2A, 00, 00, FF, 15, B0, 70, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 45, 2A...
 
[+]

Entropy:
7.9997

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file driverwhiz.exe has been seen being distributed by the following URL.

Remove driverwhiz.exe - Powered by Reason Core Security