dpinst32.exe

Driver Package Installer (DPInst)

Installer Wizard

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application dpinst32.exe, “Driver Package Installer” by Installer Wizard has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Installer Wizard)

Product:
Driver Package Installer (DPInst)

Description:
Driver Package Installer

Version:
2.1

MD5:
81755efcb5b6a41f671050ed9763e193

SHA-1:
7476c2d1e304b25a9ebbcf9b8fc6dab70c1a6e5c

SHA-256:
332b653f0ceba43dc3864f11d386f97df4eae18a5451f0612191df4ed85ee487

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 8:37:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Solvusoft.Installer.Installer.Meta (L)
15.12.20.8

File size:
539.6 KB (552,520 bytes)

Product version:
2.1

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
DPInst.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\solvusoft\driverdoc\dpinst32.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/26/2013 7:00:00 PM

Valid to:
8/26/2016 6:59:59 PM

Subject:
CN=Installer Wizard, O=Installer Wizard, STREET=848 N. Rainbow Blvd., STREET="#3321", L=Las Vegas, S=NV, PostalCode=89107, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00936840633163DBE99483CEE1F9B95E45

File PE Metadata
Compilation timestamp:
5/23/2009 5:15:06 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:/ZQaKSpwmx5ATm/LC3fwf3OoU9xkYSr/mdBTRhKWIUmPkr+LyIQju:/ZqSpwmxvL/f3vCNkPkrAyIQju

Entry address:
0x2116A

Entry point:
E8, 6C, 3C, 00, 00, E9, 1A, FE, FF, FF, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 5D, E9, 1D, 02, 00, 00, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 5D, E9, E5, FF, FF, FF, CC, CC, CC, CC, CC, 6A, 14, 68, A0, C0, 05, 01, E8, 5F, 1C, 00, 00, 83, 65, FC, 00, FF, 4D, 10, 78, 3A, 8B, 4D, 08, 2B, 4D, 0C, 89, 4D, 08, FF, 55, 14, EB, ED, 8B, 45, EC, 89, 45, E4, 8B, 45, E4, 8B, 00, 89, 45, E0, 8B, 45, E0, 81, 38, 63, 73, 6D, E0, 74, 0B, C7, 45, DC, 00, 00, 00, 00, 8B, 45, DC, C3, E8, 8C, 3C, 00, 00, 8B, 65, E8, C7, 45...
 
[+]

Entropy:
6.1691

Code size:
392 KB (401,408 bytes)

Remove dpinst32.exe - Powered by Reason Core Security