setup_driverdoc.exe

DriverDoc

Solvusoft Corporation

The application setup_driverdoc.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.solvusoft.com.
Publisher:
Solvusoft Corporation

Product:
DriverDoc

Version:
DriverDoc

MD5:
7f4a6aafad607561e02f0c3dcd913046

SHA-1:
72dcee0f429367ed124a01887b004c8428118486

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 6:38:51 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WinThruster (L)
16.8.3.20

File size:
3.4 MB (3,519,352 bytes)

Product version:
1.52.1086.14425

Copyright:
© Solvusoft Corporation

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\My documents\downloads\setup_driverdoc.exe

File PE Metadata
Compilation timestamp:
7/9/2012 4:41:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:HXX1bA+Zc3fEHebQMj0xuWq9heQXSdRZgu2AI1DW6439rNCJg1JcFNRrqIiJZGfo:3lc+ZDmJjqEz6271IkVFNRrqIZfo

Entry address:
0x16478

Entry point:
60, EB, 05, 0D, 80, 02, 65, E6, 87, D1, 81, FA, B9, E6, 00, 00, 78, 02, 88, DC, EB, 01, 42, 85, C8, 3B, CD, 0F, BE, CC, 68, DD, 2E, 66, 00, 55, 84, FD, FE, C4, 39, EF, 80, C0, 7D, C7, C0, A0, 5C, 30, 24, E8, 00, 00, 00, 00, 6B, DB, 00, 8B, F2, F2, 69, C2, E8, 6E, 6E, 8C, 8D, 2D, 69, A7, D1, 84, F7, C1, 67, 70, 80, 2B, C6, C1, 9D, FE, C4, 81, C3, 62, F3, FF, FF, 05, C7, CF, 13, 2B, 81, C3, 9F, 0C, 00, 00, 81, FF, 80, 4D, 00, 00, 78, 02, 86, C1, 0F, BF, F1, F2, 80, EE, 8D, 71, 02, 88, CD, 81, FB, 5E, 07, 00...
 
[+]

Code size:
84 KB (86,016 bytes)

The file setup_driverdoc.exe has been seen being distributed by the following URL.

Remove setup_driverdoc.exe - Powered by Reason Core Security