driverrestore.exe

Windows Setup API

Software Marketing Ltd

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application driverrestore.exe, “Windows Setup API” by Software Marketing has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
Microsoft Corporation  (signed by Software Marketing Ltd)

Product:
Microsoft® Windows® Operating System

Description:
Windows Setup API

Version:
6.1.7600.16385 (win7_rtm.090713-1255)

MD5:
fa32d00fcb48a86bbf8c49fa3f4b6c8b

SHA-1:
0488b1cfdd21b616bfc882e8c41d1a416c757aa4

SHA-256:
092d464c6f8aa0d8a72eb9edeb61afc03dd3bf4677273e8ac90ee20543abca8c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/8/2024 11:15:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SoftwareMarketing.Installer.Meta (L)
16.1.22.8

File size:
81.5 KB (83,456 bytes)

Product version:
6.1.7600.16385

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
SETUPAPI.DLL

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ultra pc care\updater\win7i386\driverrestore.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
6/14/2011 2:59:41 AM

Valid to:
6/14/2013 2:59:41 AM

Subject:
CN=Software Marketing Ltd, O=Software Marketing Ltd, L=Hong Kong, S=HK, C=HK

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B74A3CB7B3F71

File PE Metadata
Compilation timestamp:
7/14/2009 1:16:21 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
768:377hT5+KybRpnE8K74kca7NerB8iXpYmfRXvti82BSOe9oKSJ2SLD0BEZWkACLnJ:n+KY04RMmSCYmniF4O7WTCLJ

Entry address:
0x6454

Entry point:
E8, 28, 06, 00, 00, E9, C3, FD, FF, FF, CC, CC, CC, CC, CC, CC, FF, 25, 84, 11, 00, 01, CC, CC, CC, CC, CC, CC, FF, 25, E0, 11, 00, 01, CC, CC, CC, CC, CC, 3B, 0D, B0, 81, 00, 01, 75, 03, C2, 00, 00, E9, 8C, 06, 00, 00, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, CC, CC, CC, CC, CC, FF, 25, 88, 11, 00, 01, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC...
 
[+]

Code size:
27 KB (27,648 bytes)

Remove driverrestore.exe - Powered by Reason Core Security