revosetup.exe

Revo Uninstaller Setup

VS Revo Group

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from dl-web.dropbox.com and multiple other hosts.
Publisher:
VS Revo Group Ltd.  (signed by VS Revo Group)

Product:
Revo Uninstaller Setup

Version:
1.9.4.0

MD5:
979e536f75c1512ca0a13e07835a40fd

SHA-1:
bf6f4ba40d0f10646e4489b42f0ba462a3ae2089

SHA-256:
9db1d558be2f207e6ecc0f0210cf9cef0e109ead048790239b4c758ae33bab28

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/10/2024 10:11:05 AM UTC  (today)

File size:
2.5 MB (2,617,648 bytes)

Copyright:
Copyright VS Revo Group

Trademarks:
Revo Uninstaller is a trademark of VS Revo Group

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\revosetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/19/2010 4:00:00 PM

Valid to:
12/18/2013 3:59:59 PM

Subject:
CN=VS Revo Group, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=VS Revo Group, L=Ruse, S=Ruse, C=BG

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
017BF223028469B14729A770A1F0EA2D

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:DUoLE/El7CzwzVKi2EaBS8lY72jt36SOHmQtgbWW7BC:xA/Ew0z4i2tSY6SOva7g

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9923

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file revosetup.exe has been discovered within the following programs.

BitTorrent  by BitTorrent Inc.
BitTorrent is a desktop application that allows you to work with torrent files.BitTorrent allows you to download files available as torrents, search torrent sites for music, videos, books, software and other free or public domain material.
www.bittorrent.com
7% remove it
CCleaner  by Piriform
CCleaner developed by Piriform, is a utility program used to clean potentially unwanted files and invalid Windows Registry entries from a computer.
www.piriform.com/ccleaner
3% remove it
ConceptDraw MINDMAP Professional  by Computer Systems Odessa corp.
Publisher's description - “ConceptDraw MINDMAP offers a variety of outputs, making it easy to share map content in the appropriate format.”
www.conceptdraw.com/products/mind-map
8% remove it
Maxthon 3  by Maxthon International Limited
Publisher's description - “Maxthon Cloud Browser for Windows uses a unique, innovative dual-core design that uses both Webkit and Trident. Fast and efficient, our dual-core design displays all web pages quickly and reliably.”
www.maxthon.com
6% remove it
SUPERAntiSpyware  by SUPERAntiSpyware.com
SUPERAntiSpyware is a software application distributed as shareware which can detect and remove spyware, adware, trojan horses, rogue security software, computer worms, rootkits, parasites and other potentially harmful software applications.
www.superantispyware.com/support.html
25% remove it
 
Powered by Should I Remove It?

The file revosetup.exe has been seen being distributed by the following 35 URLs.

https://dl-web.dropbox.com/get/.../revo uninstaller.exe

https://tmpfile1410.s3.amazonaws.com/download77/ic_trackings/24827/.../revo-uninstaller.exe

http://download-1.com/softwares/.../revosetup_free_1.94_master.exe

http://www.fayloobmennik.net/files/.../118228358.html?check=b282d4ae1107268dfd89aa6610b55448&file=2836155

http://download-1.com/softwares/.../revosetup_free_1.94_master.exe

http://files.jalantikus.com/dde/354/.../revosetup.exe

ftp://115.112.157.36:26/.../revosetup.exe

Latest 30 of 35 download URLs

Scan revosetup.exe - Powered by Reason Core Security