driverrestore.exe

Windows Setup API

Software Marketing Ltd

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application driverrestore.exe, “Windows Setup API” by Software Marketing has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
Microsoft Corporation  (signed by Software Marketing Ltd)

Product:
Microsoft® Windows® Operating System

Description:
Windows Setup API

Version:
5.2.3790.1830 (srv03_sp1_rtm.050324-1447)

MD5:
4a02c6c46562b13d85044a5ba5e0ca1a

SHA-1:
742dfcfc284e93549cbcd01aa338976f3fd35482

SHA-256:
4d19f43f9446848c0c2ec319215caa86f10d85292787007b3348aed421fa518a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 2:42:50 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SoftwareMarketing.Installer.Meta (L)
16.1.22.8

File size:
74 KB (75,776 bytes)

Product version:
5.2.3790.1830

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
SETUPAPI.DLL

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ultra pc care\updater\amd64\driverrestore.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
6/14/2011 2:59:41 AM

Valid to:
6/14/2013 2:59:41 AM

Subject:
CN=Software Marketing Ltd, O=Software Marketing Ltd, L=Hong Kong, S=HK, C=HK

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B74A3CB7B3F71

File PE Metadata
Compilation timestamp:
3/25/2005 1:42:19 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
1536:b6eEawgsMG3zfvaPAtT9zmEb3rlxHeW8LD:bzAzfvaQT9zmU3rlxHeWE

Entry address:
0x73D0

Entry point:
48, 83, EC, 58, 48, 89, 5C, 24, 70, 48, 89, 7C, 24, 78, 66, 81, 3D, 19, 8C, FF, FF, 4D, 5A, 74, 08, 33, DB, 89, 5C, 24, 60, EB, 7C, 48, 63, 05, 44, 8C, FF, FF, 48, 8D, 0D, 01, 8C, FF, FF, 48, 03, C1, 81, 38, 50, 45, 00, 00, 74, 08, 33, DB, 89, 5C, 24, 60, EB, 5B, 0F, B7, 48, 18, 81, F9, 0B, 01, 00, 00, 74, 32, 81, F9, 0B, 02, 00, 00, 74, 08, 33, DB, 89, 5C, 24, 60, EB, 3F, 83, B8, 84, 00, 00, 00, 0E, 77, 08, 33, DB, 89, 5C, 24, 60, EB, 2E, 33, DB, 39, 98, F8, 00, 00, 00, 0F, 95, C3, 89, 5C, 24, 60, EB, 1D...
 
[+]

Code size:
31.5 KB (32,256 bytes)

Remove driverrestore.exe - Powered by Reason Core Security