devcon.exe

Windows Setup API

DriverDevelop.com

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application devcon.exe, “Windows Setup API” by DriverDevelop.com has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
Microsoft Corporation  (signed by DriverDevelop.com)

Product:
Microsoft® Windows® Operating System

Description:
Windows Setup API

Version:
6.2.9200.16384 (win8_rtm.120725-1247)

MD5:
f79769a4ff36280a118ee52d84f9640a

SHA-1:
19f88b938500558c39914f10acdce9a7f3875891

SHA-256:
d76778e60f8146144eb1dcdf47b0cd4d23d3362d8fb5e6462003a5804223d58c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 6:06:00 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.10.11.15

File size:
86 KB (88,024 bytes)

Product version:
6.2.9200.16384

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
SETUPAPI.DLL

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\devcon.exe

Digital Signature
Authority:
DriverDevelop.com

Valid from:
8/14/2009 8:02:01 PM

Valid to:
8/12/2019 8:02:01 PM

Subject:
E=ca@zndev.com, CN=DriverDevelop.com Signtools Test cert, OU=Dept. CodeSign CA, O=DriverDevelop.com, S=BeiJing, C=CN

Issuer:
E=ca@zndev.com, CN=DriverDevelop.com CA, OU=DriverDevelop.com CA, O=DriverDevelop.com, L=BeiJing, S=BeiJing, C=CN

Serial number:
011E

File PE Metadata
Compilation timestamp:
7/25/2012 6:34:56 PM

OS version:
6.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
10.10

CTPH (ssdeep):
768:YD3HTM6Y0pY/qiVZP5YuAU0xH9TLKmXj84XhF88YSQF53tnoy82BSOe9oKSJ2SLj:yPpY/qiVZKxn84XhFde73tnoyF4O7WA

Entry address:
0x6F4C

Entry point:
48, 83, EC, 28, E8, DF, 02, 00, 00, 48, 83, C4, 28, E9, 3A, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 3B, 0D, 89, 11, 00, 00, 75, 12, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 03, C2, 00, 00, 48, C1, C9, 10, E9, A4, 03, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, 40, 53, 48, 83, EC, 20, 45, 8B, 18, 48, 8B, DA, 4C, 8B, C9, 41, 83, E3, F8, 41, F6, 00, 04, 4C, 8B, D1, 74, 13, 41, 8B, 40, 08, 4D, 63, 50, 04, F7, D8, 4C, 03, D1, 48, 63, C8, 4C, 23, D1, 49, 63, C3, 4A, 8B...
 
[+]

Entropy:
5.1819

Code size:
27 KB (27,648 bytes)

Remove devcon.exe - Powered by Reason Core Security