DIRECT.EXE

Enterprise Provisioning Suite

Courion Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DIRECT!’. This is installed with DIRECT! CP.
Publisher:
Courion Corporation  (signed and verified)

Product:
Enterprise Provisioning Suite

Description:
DIRECT!® Credential Provider

Version:
8.00.00.19

MD5:
0823c2ba3c769bea9dedf483f9168b08

SHA-1:
f777b169acbc02383466b9f3a99c92421a155f12

SHA-256:
8ffd740072c3cd0fc7b29353f20109ff24b947b89549d817fce73582673395dd

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 12:52:36 AM UTC  (today)

File size:
72.9 KB (74,640 bytes)

Product version:
8.00.00.19

Copyright:
Copyright © Courion Corporation

Trademarks:
All Rights Reserved

Original file name:
DIRECT.EXE

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\courion\direct\direct.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/23/2010 8:00:00 PM

Valid to:
6/16/2013 7:59:59 PM

Subject:
CN=Courion Corporation, OU=Engineering, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Courion Corporation, L=Framingham, S=Massachusetts, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2D551D2590B024CDAA33C710A1D74D03

File PE Metadata
Compilation timestamp:
7/1/2010 4:52:38 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
768:4DiHcaTTC+Pa/QrstBB3GhnZqJ2hQQObkHOoTqMzeMwukRLW6bC1YP:4Di8aHJtpJObqW+eMwukRaCCY

Entry address:
0x6560

Entry point:
48, 83, EC, 28, E8, B7, F4, FF, FF, 48, 83, C4, 28, E9, 4E, FC, FF, FF, FF, 25, A8, 11, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, 48, 8D, 05, 61, 2D, 00, 00, 48, 89, 01, 48, 8B, C1, C3, CC, CC, 48, 89, 5C, 24, 10, 56, 48, 83, EC, 20, F6, C2, 02, 8B, F2, 48, 8B, D9, 74, 3D, 44, 8B, 41, F8, 4C, 8D, 0D, 8F, 06, 00, 00, BA, 18, 00, 00, 00, 48, 89, 7C, 24, 30, E8, 82, 03, 00, 00, 40, F6, C6, 01, 74, 09, 48, 8D, 4B, F8, E8, 4D, F7, FF, FF, 48, 8D, 43, F8, 48, 8B, 7C, 24, 30, 48, 8B, 5C, 24, 38, 48, 83, C4, 20, 5E...
 
[+]

Entropy:
5.2605

Code size:
23.5 KB (24,064 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DIRECT!

Command:
C:\Program Files\courion\direct\direct.exe


The file DIRECT.EXE has been discovered within the following program.

DIRECT! CP  by Courion Corporation
Publisher's description - “Multiple access options provide the ease of use, 24x7 availability, and flexibility to accommodate your business needs and user preferences. The options include web access, DIRECT!® desktop access, telephone, voice biometrics, secure kiosk, and service desk.”
www.Courion.com
About 5% of users remove it
 
Powered by Should I Remove It?

Scan DIRECT.EXE - Powered by Reason Core Security