drv39766.exe

win32exe

The application drv39766.exe, “win32exe installer” has been detected as a potentially unwanted program by 41 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Product:
win32exe

Description:
win32exe installer

Version:
1.0.1.111

MD5:
e3527675c8722d4c115cfe335c8e618b

SHA-1:
dffafd9b594d53fb080bdadc726f4230e1695f89

SHA-256:
12e37335da3ea68b292054f8ee04a8e30004b0a815e7f341ee587e5c7648b008

Scanner detections:
41 / 68

Status:
Potentially unwanted

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/18/2024 5:12:52 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
834

AegisLab AV Signature
Troj.W32.Gen
2.1.4+

Agnitum Outpost
Win32.Sality.BL
7.1.1

AhnLab V3 Security
Win32/Kashu.E
2014.10.14

Avira AntiVirus
W32/Sality.AT
7.11.30.172

avast!
Win32:PUP-gen [PUP]
141023-1

AVG
Adware Generic_r.TX
2014.0.4040

Baidu Antivirus
Virus.Win32.Sality.$Emu
4.0.3.141024

Bitdefender
Win32.Sality.3
1.0.20.1485

Bkav FE
W32.Sality.PE
1.3.0.4959

Comodo Security
Virus.Win32.Sality.Gen
19795

Dr.Web
hacktool program Tool.NetFilter.271
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
8.14.10.24.03

ESET NOD32
Win32/Sality.NBA virus
8.7.0.302.0

Fortinet FortiGate
W32/Agent.br!tr.dldr
10/24/2014

F-Prot
W32/Sality.E.gen
v6.4.6.5.141

F-Secure
Win32.Sality.3
11.2014-24-10_6

G Data
Win32.Sality
14.10.24

IKARUS anti.virus
Virus.Win32.Sality
t3scan.1.7.8.0

K7 AntiVirus
Virus
13.183.13662

Kaspersky
Trojan-Downloader.Win32.Agent
15.0.0.494

Malwarebytes
PUP.Optional.Amonetize
v2014.10.24.03

McAfee
W32/Sality.gen.z
5600.6968

Microsoft Security Essentials
Threat.Undefined
1.185.3018.0

MicroWorld eScan
Win32.Sality.3
15.0.0.891

NANO AntiVirus
Virus.Win32.Sality.beygb
0.28.2.62671

Norman
Sality.ZHB
11.20141024

nProtect
Virus/W32.Sality.D
14.10.12.01

Panda Antivirus
W32/Sality.AA
14.10.24.03

Qihoo 360 Security
Malware.QVM19.Gen
1.0.0.1015

Quick Heal
W32.Sality.U
10.14.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
14.10.24.3

Rising Antivirus
PE:Win32.KUKU.kt!1591113
23.00.65.141022

Sophos
Mal/Sality-D
4.98

Total Defense
Win32/Sality.AA
37.0.11225

Trend Micro House Call
PE_SALITY.RL
7.2.297

Trend Micro
PE_SALITY.RL
10.465.24

Vba32 AntiVirus
Virus.Win32.Sality.bakc
3.12.26.3

VIPRE Antivirus
Threat.4721115
33706

ViRobot
Win32.Sality.N
2011.4.7.4223

Zillya! Antivirus
Virus.Sality.Win32.20
2.0.0.1953

File size:
675 KB (691,200 bytes)

Copyright:
Copyright 2013-2014

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\drv39766.exe

File PE Metadata
Compilation timestamp:
9/16/2014 11:22:23 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:hdgmy6lZ8E9soPvow2bfZFKbY2/yiu+GCQuhhuZxkkt:hdgX6tTLafLlinQmm

Entry address:
0x14CC0

Entry point:
E8, 53, 6A, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 3D, 44, 5E, 38, 00, 00, 75, 18, E8, D1, 60, 00, 00, 6A, 1E, E8, 1B, 5F, 00, 00, 68, FF, 00, 00, 00, E8, B6, F4, FF, FF, 59, 59, 8B, 45, 08, 85, C0, 75, 01, 40, 50, 6A, 00, FF, 35, 44, 5E, 38, 00, FF, 15, 58, D1, 37, 00, 5D, C3, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 44, 5E, 38, 00, 00, 75, 18, E8, 87, 60, 00, 00, 6A, 1E, E8, D1, 5E, 00, 00, 68, FF, 00, 00, 00, E8, 6C, F4, FF, FF, 59, 59, 85, DB, 74, 04, 8B, C3...
 
[+]

Code size:
174 KB (178,176 bytes)

Remove drv39766.exe - Powered by Reason Core Security