DIRECT.EXE

Enterprise Provisioning Suite

Courion Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DIRECT!’. This is installed with DIRECT! CP.
Publisher:
Courion Corporation  (signed and verified)

Product:
Enterprise Provisioning Suite

Description:
DIRECT!® Credential Provider

Version:
8.00.00.32

MD5:
0c8f7d2faff3f4f8536b8e51bc114577

SHA-1:
5dec85721c260813516ac38d3c832d9054bb9b2e

SHA-256:
30a2fadc9018e8486d5cd4f133f18cc46982f238b2d7490ff6d8aa52abe542ac

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/2/2024 8:55:15 PM UTC  (today)

File size:
136.1 KB (139,344 bytes)

Product version:
8.00.00.32

Copyright:
Copyright © Courion Corporation

Trademarks:
All Rights Reserved

Original file name:
DIRECT.EXE

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\courion corporation\direct! credential provider\direct.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/26/2013 5:30:00 AM

Valid to:
6/25/2016 5:29:59 AM

Subject:
CN=Courion Corporation, OU=Engineering, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Courion Corporation, L=Westborough, S=Massachusetts, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0BFA859608F9B22A79E8F98EF93905C5

File PE Metadata
Compilation timestamp:
5/17/2013 11:19:39 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
1536:ap5oXaDiuWVmE9VNIdfRrCUHKiFIaoRh8pKcDrOCXem+mD+eMwPk6:apKqqVHNSRrCU/FnEupDrOCXL+mD5Ts6

Entry address:
0x6830

Entry point:
48, 83, EC, 28, E8, B7, F3, FF, FF, 48, 83, C4, 28, E9, 4E, FC, FF, FF, FF, 25, 88, 9F, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, 48, 8D, 05, 91, B9, 00, 00, 48, 89, 01, 48, 8B, C1, C3, CC, CC, 48, 89, 5C, 24, 10, 56, 48, 83, EC, 20, F6, C2, 02, 8B, F2, 48, 8B, D9, 74, 3D, 44, 8B, 41, F8, 4C, 8D, 0D, 9F, 06, 00, 00, BA, 18, 00, 00, 00, 48, 89, 7C, 24, 30, E8, 92, 03, 00, 00, 40, F6, C6, 01, 74, 09, 48, 8D, 4B, F8, E8, E9, F6, FF, FF, 48, 8D, 43, F8, 48, 8B, 7C, 24, 30, 48, 8B, 5C, 24, 38, 48, 83, C4, 20, 5E...
 
[+]

Entropy:
5.3371

Code size:
58 KB (59,392 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DIRECT!

Command:
C:\Program Files\courion corporation\direct! credential provider\direct.exe


The file DIRECT.EXE has been discovered within the following program.

DIRECT! CP  by Courion Corporation
Publisher's description - “Multiple access options provide the ease of use, 24x7 availability, and flexibility to accommodate your business needs and user preferences. The options include web access, DIRECT!® desktop access, telephone, voice biometrics, secure kiosk, and service desk.”
www.Courion.com
About 5% of users remove it
 
Powered by Should I Remove It?

Scan DIRECT.EXE - Powered by Reason Core Security