Is SoundVolumeView.exe safe?
No antivirus engine detected malware, and the verified Nir Sofer signature, established prevalence, and unpacked code strongly support authentic NirSoft software.
None of 74 antivirus engines flagged this executable, including the participating tier-1 products. It carries a verified Nir Sofer signature recognized as NirSoft, has circulated widely since 2021, and shows no malicious sandbox verdict, although two offensive-technique mappings and incomplete host reputation coverage merit acknowledgement.
4ce66c1b06bab37a85…4b8b0a9443309dRecommended next actions
Before running
Run it only when it came from the developer's official site or another source you independently trust.
If you already ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
None of 74 antivirus engines flagged this executable, including the participating tier-1 products. It carries a verified Nir Sofer signature recognized as NirSoft, has circulated widely since 2021, and shows no malicious sandbox verdict, although two offensive-technique mappings and incomplete host reputation coverage merit acknowledgement.
The strongest evidence is unanimous antivirus silence: 0 of 74 engines reported a malicious or suspicious result, with 16 tier-1 engines reporting no detection. The executable is verified as signed by Nir Sofer, and the signer matches the curated NirSoft publisher record. Its history spans 311 sources and 1,078 submissions since 2021, providing substantial prevalence rather than a newly observed profile. One sandbox produced no malicious verdict, though it mapped activity to T1055.015 and T1547.001 and recorded direct-IP traffic. Those behavioral signals are outweighed by the signature, prevalence, engine results, absence of packing, and lack of a malicious child, but no complete contacted-host reputation result is available.
What We Detected
None of 74 antivirus engines flagged the executable, and 16 tier-1 engines reported no detection. The file has a verified signature from Nir Sofer that matches the curated NirSoft publisher record. It has also been submitted 1,078 times by 311 sources since November 2021.
Threat Behavior
One completed sandbox run did not produce a malicious verdict. It did map activity to T1055.015 and T1547.001 and recorded direct-IP contacts, so these observations cannot be ignored. However, the host-reputation cross-check was not available, the code does not appear packed, and no malicious dropped child was identified; the sole YARA match, Sectigo_Code_Signed, concerns certificate metadata rather than malware behavior.
What To Do Now
Confirm that the file came from NirSoft's official distribution channel and retain normal endpoint protection. If its source is uncertain or its signature no longer validates locally, obtain a fresh copy from the official publisher rather than running that copy.
Where this verdict could be wrong3 caveats
- The completed sandbox mapped activity to T1055.015 and T1547.001, which can represent process injection and registry-run-key persistence.
- behaviour.contactedIps lists external IP traffic, while contactedHosts=null means no complete host-reputation cross-check is available.
- All 10 inspected dropped-child hashes have unknown individual verdicts despite droppedChildren.hasMaliciousChild=false.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 antivirus detections
- Verified signature from Nir Sofer
- Curated NirSoft publisher match
- 1,078 submissions from 311 sources since 2021
- No packing or high-entropy code detected
- Sandbox mapping to T1055.015
- Sandbox mapping to T1547.001
- External IP contacts without a complete host-reputation cross-check
- Ten dropped hashes lack individual verdicts
Use the executable if its local signature validates as Nir Sofer and it came from NirSoft's official channel. Keep endpoint protection enabled and replace copies obtained from untrusted sources.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial20 runtime contacts were observed without a completed reputation cross-check.
YARA
Complete3 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 20MITRE ATT&CK techniques
- 15spawned processes
- 20network contacts
- 33filesystem & mutex artifacts
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
SoundVolumeView.exe
4ce66c1b06bab37a85a93c5e7d7c9ba6f79da608fab33a00c44b8b0a9443309d
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\Desktop\executable.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
${SamplePath}\4ce66c1b06bab37a85a93c5e7d7c9ba6f79da608fab33a00c44b8b0a9443309d.exe
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
996E.cfg
C:\Documents and Settings\Administrator\Local Settings\Temp\EB93A6\996E.cfg
04Isolated runtime analysis - Written fileObserved
udhisapi.dll
C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
23.216.147.64
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
20.99.132.105
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 23.216.147.64
- 20.99.132.105
- a83f:8110:0:0:1b00:100:2800:0
- 23.216.147.76
- 192.168.0.1
- 20.99.133.109
- a83f:8110:5c00:7600:6900:6400:5f00:3000
- 192.229.211.108
- 192.168.0.27
- 23.216.81.152
- C:\Documents and Settings\Administrator\Local Settings\Temp\EB93A6\996E.cfg
- C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
- C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed
- C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed\ee190f67-126c-4768-acc3-42a00fc4e667.dat
- C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed\ee190f67-126c-4768-acc3-42a00fc4e667.dat.~tmp
- C:\Windows\System32\spp\store\2.0\cache\cache.dat
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER3071.tmp.WERInternalMetadata.xml
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER314C.tmp.csv
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER316C.tmp.txt
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER35E1.tmp.WERInternalMetadata.xml
- Global\WindowsUpdateTracingMutex
- Global\Instance0: ESENT Performance Data Schema Version 85
- CTF.LBES.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.Compart.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.Asm.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 3e0ae2be864de96650db…fb7285Never scannednever seen before
- 67226a25fe5f55195e2b…07dbdaNever scannednever seen before
- 10bfd9fefe937cc15a67…bddfe5Never scannednever seen before
- f54a6b3427d967074275…dc77a5Never scannednever seen before
- fd519efaf6949e772be6…31edc0Never scannednever seen before
- 9cb830013b4867936712…925d2dNever scannednever seen before
- e97b490fe6dcd31bb586…3deabeNever scannednever seen before
- 1a05b93295c2e34d2d88…2ac588Never scannednever seen before
- 517f14f47445db5ed88c…4933deNever scannednever seen before
- 3927ff60c7ecc262fae4…69a931Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 3rule hits recorded
- 0 / 74engines flagged
- 311sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 74 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 311 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
The file has a valid code signature from Nir Sofer.
ProvenanceObservedSourceCode-signing metadataObserved at - 04
Scanned file: SoundVolumeView.exe — 4ce66c1b06bab37a85a93c5e7d7c9ba6f79da608fab33a00c44b8b0a9443309d
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\executable.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — ${SamplePath}\4ce66c1b06bab37a85a93c5e7d7c9ba6f79da608fab33a00c44b8b0a9443309d.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: 996E.cfg — C:\Documents and Settings\Administrator\Local Settings\Temp\EB93A6\996E.cfg
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: udhisapi.dll — C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 23.216.147.64 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: 20.99.132.105 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
One or more independent reference databases matched this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
- Sectigo_Code_Signed
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
Evidence"C:\Users\<USER>\Desktop\executable.exe"The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence23.216.147.64 · 20.99.132.105 · a83f:8110:0:0:1b00:100:2800:0
0 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- SoundVolumeView.exe
- Format
- Win32 EXE
- Code signing
- Signature valid: Nir Sofer
- Size
- 139.9 KB
- Last analyzed
- Sep 12, 2026, 9:06 PM UTC
4ce66c1b06bab37a85a93c5e7d7c9ba6f79da608fab33a00c44b8b0a9443309dSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Run it only when it came from the developer's official site or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is SoundVolumeView.exe safe?
What is SoundVolumeView.exe?
How many antivirus engines detected SoundVolumeView.exe?
Is SoundVolumeView.exe digitally signed?
What is the SHA-256 hash of SoundVolumeView.exe?
Is it safe to run SoundVolumeView.exe?
How up to date is this analysis of SoundVolumeView.exe?
Community
Member reviews and reports for this exact file hash.