pcreviversetup.exe

PC Reviver

Corel Corporation

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is installed with PC Reviver. The file has been seen being downloaded from www.reviversoft.com and multiple other hosts.
Publisher:
ReviverSoft LLC  (signed by Corel Corporation)

Product:
PC Reviver

Description:
PC Reviver installer

Version:
2.6.0.10

MD5:
9585075bb5e9cbc769be0417a21e0886

SHA-1:
054a8a15e38dc85e487151b81357dfc95b20f0ff

SHA-256:
d1c816343975225166d38ec5523ad45a717952576a15fed45b57069af452f0c6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 8:11:01 PM UTC  (today)

File size:
25.4 MB (26,625,568 bytes)

Product version:
2.6.0.10

Copyright:
Copyright (c) 2016 ReviverSoft LLC. All Rights Reserved.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\pcreviversetup.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
7/31/2015 6:00:00 PM

Valid to:
7/31/2016 5:59:59 PM

Subject:
CN=Corel Corporation, O=Corel Corporation, L=Ottawa, S=Ontario, C=CA

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
4A1405278B355E198E080E13B0A8E885

File PE Metadata
Compilation timestamp:
4/10/2010 6:19:31 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
786432:8EgZbnnpFTP7H7wLQMQZzTT8i7rCiBCinS:8/nPP7bjTn73BPS

Entry address:
0x354B

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 84, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 98, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 86, 40, 00, FF, 15, 80, 81, 40, 00, 68, 04, 86, 40, 00, 68, A0, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Entropy:
7.9999

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file pcreviversetup.exe has been discovered within the following program.

PC Reviver  by ReviverSoft LLC
39% remove it
 
Powered by Should I Remove It?

The file pcreviversetup.exe has been seen being distributed by the following 5 URLs.

http://www.reviversoft.com/.../PCReviverSetup.exe