solvusoftdd.exe

DriverDoc

Installer Genius (Solvusoft Corporation)

The application solvusoftdd.exe by Installer Genius (Solvusoft) has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler named DriverDocRunAtStartup triggered to execute each time a user logs in. This file is typically installed with the program DriverDoc by Solvusoft Corporation.
Publisher:
Solvusoft Corporation  (signed by Installer Genius (Solvusoft Corporation))

Product:
DriverDoc

Version:
2.25.1086.16624

MD5:
f869c196b4f4830e1692c4fc6e1d4e77

SHA-1:
3d971d48b2042484711a0f9dac7b29729c87404b

SHA-256:
e9a5309f421ecbad9a79060fe36c21192843188859cc939cd43b867269ee88ca

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
10/23/2017 9:40:02 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallerGenius.InstallerGeniusSolvusoftCorporation.Meta (L)
16.1.4.20

File size:
8.4 MB (8,803,968 bytes)

Product version:
2.25.1086.16624

Copyright:
© Solvusoft Corporation 2012- 13 - All rights reserved, Portions © Systweak Inc.

Trademarks:
DriverDoc

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\driverdoc\solvusoftdd.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
9/30/2015 2:00:00 AM

Valid to:
9/30/2016 1:59:59 AM

Subject:
CN=Installer Genius (Solvusoft Corporation), O=Installer Genius (Solvusoft Corporation), STREET="848 N. RAINBOW BLVD #3321", L=Las Vegas, S=Nevada, PostalCode=89107, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
161DD9A8ED08BBED847F70DA0143AF5F

File PE Metadata
Compilation timestamp:
4/10/2015 2:50:21 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:vvtQm58t+aIryJuunROg2GkH7VTb1ZODhwSgP+/kqZYB:NH2LBJLRJ2vhb1oYB

Entry address:
0x105B5C

Entry point:
E8, F9, B1, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, A8, F7, 68, 00, 75, 02, F3, C3, E9, 7B, B2, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, A3, 6A, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, AE, 06, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 41, B3, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 80, 71, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73...
 
[+]

Code size:
2.1 MB (2,247,680 bytes)

Scheduled Task
Task name:
DriverDocRunAtStartup

Trigger:
Logon (Runs on logon)


The file solvusoftdd.exe has been discovered within the following program.

DriverDoc  by Solvusoft Corporation
www.solvusoft.com
About 4% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to s3-1-w.amazonaws.com  (52.216.0.112:80)

TCP (HTTP):
Connects to dd.e7.25ae.ip4.static.sl-reverse.com  (174.37.231.221:80)

Remove solvusoftdd.exe - Powered by Reason Core Security