SuiteService.exe

Solvusoft Suite

Installer Wizard

The application SuiteService.exe, “Solvusoft Suite Service” by Installer Wizard has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address web30.cluster.spamfighter.com on port 80 using the HTTP protocol.
Publisher:
Solvusoft Corporation  (signed by Installer Wizard)

Product:
Solvusoft Suite

Description:
Solvusoft Suite Service

Version:
3.1.293.0

MD5:
1f3994775fb5bb35679040c927386cf6

SHA-1:
da109c3b736c5a75770b8b85c0f73514adc174c6

SHA-256:
8a28a99338cdc6e81aa86a4d7723222c88cd4c8a6251241bcd7d5acbdb253e2f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/24/2025 11:10:41 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Solvusoft.Installer (L)
17.2.7.15

File size:
1.2 MB (1,284,168 bytes)

Product version:
3.1.293.0

Copyright:
Copyright (C) 2003, 2009 Solvusoft Corporation

Original file name:
SuiteService.exe

File type:
Executable application (Win32 EXE)

Language:
Ukrainian (Ukraine)

Common path:
C:\Program Files\solvusoft\suiteservice.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/27/2013 2:00:00 AM

Valid to:
8/27/2016 1:59:59 AM

Subject:
CN=Installer Wizard, O=Installer Wizard, STREET=848 N. Rainbow Blvd., STREET="#3321", L=Las Vegas, S=NV, PostalCode=89107, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00936840633163DBE99483CEE1F9B95E45

File PE Metadata
Compilation timestamp:
11/13/2015 7:42:15 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

Entry address:
0x95EF7

Entry point:
E8, 54, DA, 00, 00, E9, A5, FE, FF, FF, 6A, 0C, 68, 08, 3D, 4F, 00, E8, B7, 07, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, B8, 79, 52, 00, 77, 22, 6A, 04, E8, 11, 96, 00, 00, 59, 83, 65, FC, 00, 56, E8, 18, 9E, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, C3, 07, 00, 00, C3, 6A, 04, E8, 0C, 95, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87, A1, 00, 00, 00, 53, 57, 8B, 3D, 0C, A2, 4D, 00, 83, 3D, 0C, 6B, 52, 00, 00, 75, 18, E8, A8, B4, 00...
 
[+]

Entropy:
6.4858

Code size:
864.5 KB (885,248 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to web40.cluster.spamfighter.com  (91.192.52.195:80)

TCP (HTTP):
Connects to web30.cluster.spamfighter.com  (91.192.52.205:80)

Remove SuiteService.exe - Powered by Reason Core Security