dpinst32.exe

Instalator pakietu sterowników (DPInst)

LionSea Software co., ltd

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application dpinst32.exe, “Instalator pakietu sterowników” by LionSea Software co., ltd has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by LionSea Software co., ltd)

Product:
Instalator pakietu sterowników (DPInst)

Description:
Instalator pakietu sterowników

Version:
2.1

MD5:
5eadeecfa5950218e9ef55e2139d026c

SHA-1:
01dc4b750e2279b0aa003848d6b5a33126b38a17

SHA-256:
94d463c21a73a081b84332e84a29066b1b4f54a8a428a6d5f70084d0f24f2ea8

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 5:12:12 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.LionSea.LionSeaSoftwareco (M)
16.2.11.22

File size:
775.8 KB (794,424 bytes)

Product version:
2.1

Copyright:
© Microsoft Corporation. Wszelkie prawa zastrzeżone.

Original file name:
DPInst.exe.mui

File type:
Executable application (Win32 EXE)

Language:
Polish (Poland)

Common path:
C:\Program Files\computer drivers download utility\dpinst32.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/22/2013 1:00:00 AM

Valid to:
3/24/2016 12:59:59 AM

Subject:
CN="LionSea Software co., ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="LionSea Software co., ltd", L=beijing, S=beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
288A6842C331C5443D747BDABF31E2A3

File PE Metadata
Compilation timestamp:
10/17/2006 1:47:22 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:w2BG1lkWPemh/CsOs5Un05pJg6fjlhFbLdG3sBtbIPjVXH+u8s5NwOPL6Q:Xc19PtCsOsCn01g6L9aPM26OPH

Entry address:
0x213B9

Entry point:
E8, 2D, 3B, 00, 00, E9, 1A, FE, FF, FF, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 5D, E9, F6, 01, 00, 00, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 5D, E9, E5, FF, FF, FF, CC, CC, CC, CC, CC, 6A, 14, 68, C0, BB, 05, 01, E8, E8, 1B, 00, 00, 83, 65, FC, 00, FF, 4D, 10, 78, 3A, 8B, 4D, 08, 2B, 4D, 0C, 89, 4D, 08, FF, 55, 14, EB, ED, 8B, 45, EC, 89, 45, E4, 8B, 45, E4, 8B, 00, 89, 45, E0, 8B, 45, E0, 81, 38, 63, 73, 6D, E0, 74, 0B, C7, 45, DC, 00, 00, 00, 00, 8B, 45, DC, C3, E8, 41, 3B, 00, 00, 8B, 65, E8, C7, 45...
 
[+]

Code size:
391 KB (400,384 bytes)

Remove dpinst32.exe - Powered by Reason Core Security