driverrestore.exe

Windows Setup API

Software Marketing Ltd

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application driverrestore.exe, “Windows Setup API” by Software Marketing has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
Microsoft Corporation  (signed by Software Marketing Ltd)

Product:
Microsoft® Windows® Operating System

Description:
Windows Setup API

Version:
6.0.6000.16386 (vista_rtm.061101-2205)

MD5:
13e5a45616360868146cf69dbba259dc

SHA-1:
a1f20ec257fe04e218325bb682e71450d645f780

SHA-256:
5ebfa00043f5ded6c4bc250357f5b94a628035492ff97817ec89e23b557a062e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 10:19:04 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SoftwareMarketing.Installer.Meta (L)
16.1.22.8

File size:
81 KB (82,944 bytes)

Product version:
6.0.6000.16386

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
SETUPAPI.DLL

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ultra pc care\updater\vista\driverrestore.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
6/14/2011 2:59:41 AM

Valid to:
6/14/2013 2:59:41 AM

Subject:
CN=Software Marketing Ltd, O=Software Marketing Ltd, L=Hong Kong, S=HK, C=HK

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B74A3CB7B3F71

File PE Metadata
Compilation timestamp:
11/2/2006 9:33:23 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
768:VBVg66plPNWeHXPKT048dBlHSS+BN8Z3+b26v82BSOe9oKSJ2SLD0BEZWk2aMLn9:3VZqlP8O4SrSSo8Z3+y6vF4O7WhhL9

Entry address:
0x62AF

Entry point:
E8, 2A, 06, 00, 00, E9, B6, FD, FF, FF, CC, CC, CC, CC, CC, FF, 25, 84, 11, 00, 01, CC, CC, CC, CC, CC, CC, FF, 25, E4, 11, 00, 01, CC, CC, CC, CC, CC, 3B, 0D, B0, 81, 00, 01, 75, 02, F3, C3, E9, 84, 06, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, CC, CC, CC, CC, CC, FF, 25, 8C, 11, 00, 01, CC, CC, CC, CC, CC, CC, CC, CC, CC...
 
[+]

Code size:
26.5 KB (27,136 bytes)

Remove driverrestore.exe - Powered by Reason Core Security