vs89h2pg.002

DriverAutoInstall

drivermagician.com

The file vs89h2pg.002, “Drivers Auto-Install of Driver Magician” by drivermagician.com has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
GoldSolution Software, Inc.  (signed by drivermagician.com)

Product:
DriverAutoInstall

Description:
Drivers Auto-Install of Driver Magician

Version:
3.31

MD5:
06cf2f5f42987ea3cf317645b8d573dc

SHA-1:
c0228d9976fa357ae057f85a5606ffc5caa00b80

SHA-256:
446c1acdb3d9600ed0227ff5a63f69e76148ed20cd7485c29750b3ad61279019

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 8:07:57 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.12.31.4

File size:
660.6 KB (676,496 bytes)

Product version:
3.31

Copyright:
GoldSolution Software, Inc.2003-2008

Original file name:
DriverAutoInstall.exe

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\hc_attk\vs89h2pg.002

Digital Signature
Authority:
WoSign, Inc.

Valid from:
6/5/2007 12:00:00 PM

Valid to:
6/5/2009 11:59:59 AM

Subject:
CN=drivermagician.com, OU=Class 2 - for Microsoft Authenticode Signing, OU=Domain Control Validated, O=drivermagician.com

Issuer:
CN=WoSign Code Signing Authority, O="WoSign, Inc.", C=US

Serial number:
00B190558A17E22B229C4989668F434250

File PE Metadata
Compilation timestamp:
8/14/2008 7:34:22 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1134

Entry point:
68, A4, 12, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 48, 00, 00, 00, 00, 00, 00, 00, 67, 7A, 80, 59, 70, 81, 4E, 42, AC, D4, A2, 11, AA, 53, 35, 45, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 50, 00, 00, 00, 00, 44, 72, 69, 76, 65, 72, 41, 75, 74, 6F, 49, 6E, 73, 74, 61, 6C, 6C, 00, 72, 00, 73, 00, 69, 00, 00, 00, 00, 00, 01, 00, 04, 00, 78, 30, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, 8C, 31, 40, 00, 54, C0, 41, 00, 05, 00, 00, 00, E4, 11, 40, 00...
 
[+]

Entropy:
6.1688

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
108 KB (110,592 bytes)

Remove vs89h2pg.002 - Powered by Reason Core Security