driverrestore.exe

Windows Setup API

Software Marketing Ltd

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application driverrestore.exe, “Windows Setup API” by Software Marketing has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software.
Publisher:
Microsoft Corporation  (signed by Software Marketing Ltd)

Product:
Microsoft® Windows® Operating System

Description:
Windows Setup API

Version:
5.2.3718.0 (dnsrv.021114-1947)

MD5:
2b5d0a324544fd44cdea5c6b35c583a4

SHA-1:
21a51aa5db152f9f2954f8b09e6d7b64c46ecfc6

SHA-256:
5f49dde3fdf528253f430788ecf0b5b64818b67cf2d6cfcbedcd77db8795cc53

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
8/14/2025 1:07:10 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SoftwareMarketing.Installer.Meta (L)
16.1.22.8

File size:
60 KB (61,440 bytes)

Product version:
5.2.3718.0

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
SETUPAPI.DLL

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ultra pc care\updater\xp\driverrestore.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
6/14/2011 2:59:41 AM

Valid to:
6/14/2013 2:59:41 AM

Subject:
CN=Software Marketing Ltd, O=Software Marketing Ltd, L=Hong Kong, S=HK, C=HK

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B74A3CB7B3F71

File PE Metadata
Compilation timestamp:
11/15/2002 7:32:05 AM

OS version:
5.2

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
7.10

CTPH (ssdeep):
768:5gEuhGUsQ9Z7lVQpjagwpKsQt2IJU1evxHs4gZWkyLn4I:W1/9ZisQtBU4xHeWfLb

Entry address:
0x5211

Entry point:
6A, 28, 68, C8, 15, 00, 01, E8, F3, 01, 00, 00, 66, 81, 3D, 00, 00, 00, 01, 4D, 5A, 75, 28, A1, 3C, 00, 00, 01, 81, B8, 00, 00, 00, 01, 50, 45, 00, 00, 75, 17, 0F, B7, 88, 18, 00, 00, 01, 81, F9, 0B, 01, 00, 00, 74, 21, 81, F9, 0B, 02, 00, 00, 74, 06, 83, 65, E4, 00, EB, 2A, 83, B8, 84, 00, 00, 01, 0E, 76, F1, 33, C9, 39, 88, F8, 00, 00, 01, EB, 11, 83, B8, 74, 00, 00, 01, 0E, 76, DE, 33, C9, 39, 88, E8, 00, 00, 01, 0F, 95, C1, 89, 4D, E4, 83, 65, FC, 00, 6A, 01, FF, 15, 7C, 11, 00, 01, 59, 83, 0D, CC, 61...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
20 KB (20,480 bytes)

Remove driverrestore.exe - Powered by Reason Core Security