dpinst64.exe

Driver Package Installer (DPInst)

LionSea Software co., ltd

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application dpinst64.exe, “Driver Package Installer” by LionSea Software co., ltd has been detected as a potentially unwanted program by 10 anti-malware scanners.
Publisher:
Microsoft Corporation  (signed by LionSea Software co., ltd)

Product:
Driver Package Installer (DPInst)

Description:
Driver Package Installer

Version:
2.1

MD5:
4435aa96811cfc209f5463744fe4766d

SHA-1:
a8517e14cb213862e6f5ea0b5596bb66bc4624b6

SHA-256:
d0473be812acf31c0374369c2b5d951b9088248b581b74da45dad51f4c21b042

Scanner detections:
10 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 3:12:42 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
riskware program Program.Unwanted.79
9.0.1.043

F-Prot
W32/HLLP.41472
v6.4.6.5.141

Malwarebytes
Trojan.Agent
v2016.02.12.08

McAfee
W32/HLLP.41472.e
5600.6492

MicroWorld eScan
Win32.Neshta.A
17.0.0.129

NANO AntiVirus
Virus.Win32.Neshta.cdby
0.26.0.53954

Norman
Neshta.C
11.20160212

nProtect
Virus/W32.Neshta
13.08.21.03

Quick Heal
W32.Neshta.A
2.16.12.00

Reason Heuristics
PUP.LionSea.LionSeaSoftwareco.Installer (M)
16.2.12.8

File size:
907.8 KB (929,592 bytes)

Product version:
2.1

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
DPInst.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ibm drivers download utility\dpinst64.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/22/2013 5:30:00 AM

Valid to:
3/24/2016 5:29:59 AM

Subject:
CN="LionSea Software co., ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="LionSea Software co., ltd", L=beijing, S=beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
288A6842C331C5443D747BDABF31E2A3

File PE Metadata
Compilation timestamp:
10/17/2006 5:27:22 AM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:ScQsynWrZI8I/VELVqZFbq+0pHKmdTJF805CbLLDFSQSAj99HJYnJzDX+v34nQTa:RpRkVWqZRqXVI0oLD7ZxA434QTPh2F

Entry address:
0x6BD3C

Entry point:
48, 83, EC, 28, E8, 2F, 09, 00, 00, 48, 83, C4, 28, E9, B6, FC, FF, FF, CC, CC, CC, CC, CC, CC, FF, 25, 2E, 5C, F9, FF, CC, CC, CC, CC, CC, CC, FF, 25, 1A, 5C, F9, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 66, 90, 66, 66, 66, 90, 66, 90, 48, 3B, 0D, B1, 73, 01, 00, 75, 11, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 02, F3, C3, 48, C1, C9, 10, E9, 91, 09, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, 48, 89, 5C, 24, 10, 44, 89, 44, 24, 18, 48, 89, 4C, 24, 08, 56, 57, 41, 54, 48...
 
[+]

Entropy:
5.7351

Code size:
517 KB (529,408 bytes)

Remove dpinst64.exe - Powered by Reason Core Security