DIRECT.EXE

Enterprise Provisioning Suite

Courion Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DIRECT!’. This is installed with DIRECT! CP.
Publisher:
Courion Corporation  (signed and verified)

Product:
Enterprise Provisioning Suite

Description:
DIRECT!® Credential Provider

Version:
8.00.00.02

MD5:
4cb30cebd70e39702adf2126103df06b

SHA-1:
b8b71a26e2712d17aafc51324f0180b59e55a5c2

SHA-256:
ca09e8fa754978f45590cd2c8b41804b5a5a5fa9993fab5724aa3805949f3d80

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/5/2024 11:46:46 PM UTC  (a few moments ago)

File size:
71.8 KB (73,544 bytes)

Product version:
8.00.00.02

Copyright:
Copyright © Courion Corporation

Trademarks:
All Rights Reserved

Original file name:
DIRECT.EXE

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\courion corporation\direct! cp\direct.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/18/2007 6:00:00 PM

Valid to:
6/17/2010 5:59:59 PM

Subject:
CN=Courion Corporation, OU=Engineering, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Courion Corporation, L=Framingham, S=Massachusetts, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0F3B138B8C5897F77474E09F2F58285D

File PE Metadata
Compilation timestamp:
10/8/2008 9:31:29 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
768:hEtSMH+7TWfzCaGpwM5sQQB3GIRdOqDFjQQORmBHOo1qMzeMw8kM6VLAJbM:WtSMHbfzCl1ncd95ORSs+eMw8kN+M

Entry address:
0x63B0

Entry point:
48, 83, EC, 28, E8, C7, F4, FF, FF, 48, 83, C4, 28, E9, 4E, FC, FF, FF, FF, 25, 40, 13, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, 48, 8D, 05, F1, 2E, 00, 00, 48, 89, 01, 48, 8B, C1, C3, CC, CC, 48, 89, 5C, 24, 10, 56, 48, 83, EC, 20, F6, C2, 02, 8B, F2, 48, 8B, D9, 74, 3D, 44, 8B, 41, F8, 4C, 8D, 0D, 8F, 06, 00, 00, BA, 18, 00, 00, 00, 48, 89, 7C, 24, 30, E8, 82, 03, 00, 00, 40, F6, C6, 01, 74, 09, 48, 8D, 4B, F8, E8, 5D, F7, FF, FF, 48, 8D, 43, F8, 48, 8B, 7C, 24, 30, 48, 8B, 5C, 24, 38, 48, 83, C4, 20, 5E...
 
[+]

Entropy:
5.2657

Code size:
23 KB (23,552 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DIRECT!

Command:
C:\Program Files\courion corporation\direct! cp\direct.exe


The file DIRECT.EXE has been discovered within the following program.

DIRECT! CP  by Courion Corporation
Publisher's description - “Multiple access options provide the ease of use, 24x7 availability, and flexibility to accommodate your business needs and user preferences. The options include web access, DIRECT!® desktop access, telephone, voice biometrics, secure kiosk, and service desk.”
www.Courion.com
About 5% of users remove it
 
Powered by Should I Remove It?

Scan DIRECT.EXE - Powered by Reason Core Security