devcon.exe

Windows Setup API

Promelement, LLC

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application devcon.exe, “Windows Setup API” by Promelement has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Promelement, LLC)

Product:
Microsoft® Windows® Operating System

Description:
Windows Setup API

Version:
6.2.9200.16384 (win8_rtm.120725-1247)

MD5:
eea7fb9b21e0539c5c6f2da3a9d45c2d

SHA-1:
e909db0c7ce28a348515ac6af8cab7e49a04f2a0

SHA-256:
6f9345bc61e16619266ed96bdf17a5754402e232271500e26ce1cbab8fa76d1b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 1:03:38 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Promelement.Installer (M)
16.3.3.1

File size:
88.4 KB (90,504 bytes)

Product version:
6.2.9200.16384

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
SETUPAPI.DLL

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\emul64\devcon.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
1/22/2013 7:00:00 AM

Valid to:
1/29/2014 7:00:00 PM

Subject:
CN="Promelement, LLC", O="Promelement, LLC", L=Chelyabinsk, S=Chelyabinsk, C=RU

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0FDBA32CE8DC0EF00F7C962DB173BC55

File PE Metadata
Compilation timestamp:
7/26/2012 8:34:56 AM

OS version:
6.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
10.10

CTPH (ssdeep):
1536:ePpY/qiVZKxn84XhFde73tnoyF4O7WNjj:/AJjde7doMRWd

Entry address:
0x6F4C

Entry point:
48, 83, EC, 28, E8, DF, 02, 00, 00, 48, 83, C4, 28, E9, 3A, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 3B, 0D, 89, 11, 00, 00, 75, 12, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 03, C2, 00, 00, 48, C1, C9, 10, E9, A4, 03, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, 40, 53, 48, 83, EC, 20, 45, 8B, 18, 48, 8B, DA, 4C, 8B, C9, 41, 83, E3, F8, 41, F6, 00, 04, 4C, 8B, D1, 74, 13, 41, 8B, 40, 08, 4D, 63, 50, 04, F7, D8, 4C, 03, D1, 48, 63, C8, 4C, 23, D1, 49, 63, C3, 4A, 8B...
 
[+]

Entropy:
5.1976

Code size:
27 KB (27,648 bytes)

Remove devcon.exe - Powered by Reason Core Security