dpinst64.exe

Instalator pakietu sterowników (DPInst)

LionSea Software co., ltd

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application dpinst64.exe, “Instalator pakietu sterowników” by LionSea Software co., ltd has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by LionSea Software co., ltd)

Product:
Instalator pakietu sterowników (DPInst)

Description:
Instalator pakietu sterowników

Version:
2.1

MD5:
611bc61c32b2fe148fdca918fa104b24

SHA-1:
299eae12f04ec921c3080be8c4f3f19af40cc2e0

SHA-256:
41c13f12961b95c5fb0ae63e012cad4a7e4d3848750193b897637cf4a8fcf7e6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 11:12:21 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.LionSea.LionSeaSoftwareco (M)
16.2.11.22

File size:
907.8 KB (929,592 bytes)

Product version:
2.1

Copyright:
© Microsoft Corporation. Wszelkie prawa zastrzeżone.

Original file name:
DPInst.exe.mui

File type:
Executable application (Win64 EXE)

Language:
Polish (Poland)

Common path:
C:\Program Files\computer drivers download utility\dpinst64.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/22/2013 1:00:00 AM

Valid to:
3/24/2016 12:59:59 AM

Subject:
CN="LionSea Software co., ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="LionSea Software co., ltd", L=beijing, S=beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
288A6842C331C5443D747BDABF31E2A3

File PE Metadata
Compilation timestamp:
10/17/2006 1:57:22 AM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:vcQsynWrZI8I/VELVqZFbq+0pHKmdTJF805CbLLDFSQSAj99HJYnJzDX+v34nQTt:EpRkVWqZRqXVI0oLD7ZxA434QTPh2e

Entry address:
0x6BD3C

Entry point:
48, 83, EC, 28, E8, 2F, 09, 00, 00, 48, 83, C4, 28, E9, B6, FC, FF, FF, CC, CC, CC, CC, CC, CC, FF, 25, 2E, 5C, F9, FF, CC, CC, CC, CC, CC, CC, FF, 25, 1A, 5C, F9, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 66, 90, 66, 66, 66, 90, 66, 90, 48, 3B, 0D, B1, 73, 01, 00, 75, 11, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 02, F3, C3, 48, C1, C9, 10, E9, 91, 09, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, 48, 89, 5C, 24, 10, 44, 89, 44, 24, 18, 48, 89, 4C, 24, 08, 56, 57, 41, 54, 48...
 
[+]

Code size:
517 KB (529,408 bytes)

Remove dpinst64.exe - Powered by Reason Core Security