dpinst32.exe

Programme d'installation du package de pilotes (DPInst)

LionSea Software co., ltd

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application dpinst32.exe, “Programme d'installation du package de pilotes” by LionSea Software co., ltd has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
Microsoft Corporation  (signed by LionSea Software co., ltd)

Product:
Programme d'installation du package de pilotes (DPInst)

Description:
Programme d'installation du package de pilotes

Version:
2.1

MD5:
6f0528bb50b448c95c32f7330c822aef

SHA-1:
328260f3bcaa4dc7e9d0d8d1a48ffd508d730797

SHA-256:
5b5478c20084583dad42ccef642c756bf8efe75887d7cd441519041a82e3105b

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/23/2024 5:44:31 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
riskware program Program.Unwanted.79
9.0.1.046

Reason Heuristics
PUP.LionSea.LionSeaSoftwareco (M)
16.2.15.18

File size:
775.8 KB (794,424 bytes)

Product version:
2.1

Copyright:
© Microsoft Corporation. Tous droits réservés.

Original file name:
DPInst.exe.mui

File type:
Executable application (Win32 EXE)

Language:
French (France)

Common path:
C:\Program Files\lexmark drivers download utility\dpinst32.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/22/2013 12:00:00 AM

Valid to:
3/23/2016 11:59:59 PM

Subject:
CN="LionSea Software co., ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="LionSea Software co., ltd", L=beijing, S=beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
288A6842C331C5443D747BDABF31E2A3

File PE Metadata
Compilation timestamp:
10/17/2006 12:47:22 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:D2BG1lkWPemh/CsOs5Un05pJg6fjlhFbLdG3sBtbIPjVXH+u8s5NwOPL6E:ic19PtCsOsCn01g6L9aPM26OPD

Entry address:
0x213B9

Entry point:
E8, 2D, 3B, 00, 00, E9, 1A, FE, FF, FF, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 5D, E9, F6, 01, 00, 00, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 5D, E9, E5, FF, FF, FF, CC, CC, CC, CC, CC, 6A, 14, 68, C0, BB, 05, 01, E8, E8, 1B, 00, 00, 83, 65, FC, 00, FF, 4D, 10, 78, 3A, 8B, 4D, 08, 2B, 4D, 0C, 89, 4D, 08, FF, 55, 14, EB, ED, 8B, 45, EC, 89, 45, E4, 8B, 45, E4, 8B, 00, 89, 45, E0, 8B, 45, E0, 81, 38, 63, 73, 6D, E0, 74, 0B, C7, 45, DC, 00, 00, 00, 00, 8B, 45, DC, C3, E8, 41, 3B, 00, 00, 8B, 65, E8, C7, 45...
 
[+]

Code size:
391 KB (400,384 bytes)

Remove dpinst32.exe - Powered by Reason Core Security