dpinst64.exe

Driver Package Installer (DPInst)

Installer Wizard

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application dpinst64.exe, “Driver Package Installer” by Installer Wizard has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Installer Wizard)

Product:
Driver Package Installer (DPInst)

Description:
Driver Package Installer

Version:
2.1

MD5:
8bdc924e4973bff054ab9d9ee2a5f534

SHA-1:
8ae4945641df731bdae3de40085257bb45d57dfc

SHA-256:
ee42bde216164421c2cadff7b7cde3b308a9a7c5252cbd098871047b793a4323

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/16/2024 4:23:25 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Solvusoft.Installer.Installer.Meta (L)
15.12.20.8

File size:
662.1 KB (677,960 bytes)

Product version:
2.1

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
DPInst.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\solvusoft\driverdoc\dpinst64.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/26/2013 7:00:00 PM

Valid to:
8/26/2016 6:59:59 PM

Subject:
CN=Installer Wizard, O=Installer Wizard, STREET=848 N. Rainbow Blvd., STREET="#3321", L=Las Vegas, S=NV, PostalCode=89107, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00936840633163DBE99483CEE1F9B95E45

File PE Metadata
Compilation timestamp:
5/23/2009 5:37:17 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:XsW7OzpPId26dQcEaUrPvwgwkRVagRoOQTiHaQsVIhVLpHf2mmPr:JIId79EaUTvwieMowXzZ2tPr

Entry address:
0x5CBA8

Entry point:
48, 83, EC, 28, E8, 8F, 08, 00, 00, 48, 83, C4, 28, E9, D2, FC, FF, FF, CC, CC, CC, CC, CC, CC, FF, 25, 02, 4E, FA, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 3B, 0D, 51, 45, 02, 00, 75, 12, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 03, C2, 00, 00, 48, C1, C9, 10, E9, FC, 08, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, 48, 89, 5C, 24, 10, 44, 89, 44, 24, 18, 48, 89, 4C, 24, 08, 56, 57, 41, 54, 48, 83, EC, 40, 49, 8B, F1, 41, 8B, F8, 4C, 8B, E2...
 
[+]

Entropy:
5.9330

Code size:
510.5 KB (522,752 bytes)

Remove dpinst64.exe - Powered by Reason Core Security