How to remove DiscSoftBusServiceLite.exe

DiscSoftBusServiceLite.exe

The module DiscSoftBusServiceLite.exe has been detected as Trojan.Heur!

DiscSoftBusServiceLite.exe

DiscSoftBusServiceLite.exe is a Windows file recorded in the ThreatInfo database. It is associated with DAEMON Tools Lite. The reported company name is Disc Soft Ltd. The current detection status is Trojan.Heur!, based on the latest analysis from 2023-06-01 23:23:41 (2 years ago).

If DiscSoftBusServiceLite.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Heur!.

Product Name: DAEMON Tools Lite
Company Name: Disc Soft Ltd
MD5: 4500f890a8b2955b8b2f5617142aaed7
Size: 4 MB
First Published: 2023-06-01 23:19:21 (2 years ago)
Latest Published: 2023-06-01 23:23:41 (2 years ago)
Status: Trojan.Heur! (on last analysis)
Analysis Date: 2023-06-01 23:23:41 (2 years ago)
Signed By: AVB Disc Soft, SIA
Status: Valid

The signature on DiscSoftBusServiceLite.exe is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%programfiles%
%system%
%system%

ThreatInfo has observed DiscSoftBusServiceLite.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Argentina with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for DiscSoftBusServiceLite.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

DiscSoftBusServiceLite.exe is identified as pe for 64 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x00290a64

PE Sections:

Name Size of data MD5
.text 3581952 3e1008e2e0e7cf4f18e0f44609bf80d5
APE_C 11264 d5a42b0316c0fedae61c88a9737ca98d
FLAC_C 5632 3ec2989d80e3d624c97cf8369235b7f6
ZLIB_C 10752 6518d740c7cdcfbb76dc9aab84c58f16
.rdata 580608 30de2d24d063253ae26eb252390c8b8b
.data 58880 aa1f3d565b8a79124369c173f1f68bb5
.pdata 181760 a90cb089d3fc0b5134869ee52b4a12f8
_RDATA 512 dbcae9f41d9f33431079100accc74880
.vmp0 287232 3a4284dafd5f9f2ab585e71a0fc0be75
.reloc 13312 991435514fd0310167fcb71361aab751
.rsrc 217600 c7f0b0901e6c79e7d448d5dcd4411d25

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information:

Download GridinSoft Anti-Malware - Removal tool for DiscSoftBusServiceLite.exe