driverrestore.exe

Windows Setup API

Utililab GmbH

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application driverrestore.exe, “Windows Setup API” by Utililab GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Utililab GmbH)

Product:
Microsoft® Windows® Operating System

Description:
Windows Setup API

Version:
5.2.3790.1830 (srv03_sp1_rtm.050324-1447)

MD5:
5a6fddbb554ce4c3313c4748141e81ec

SHA-1:
cda441dcac312ac8b51e92b6d3e84d366c8a4aba

SHA-256:
31ba7228692b9b274788bee1d46335bf0aef8f264ee243575ee37027577974d9

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 11:56:39 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Utililab.SystemOptimizer.Optional.Installer.Meta (L)
16.2.5.16

File size:
73.1 KB (74,896 bytes)

Product version:
5.2.3790.1830

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
SETUPAPI.DLL

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\utililab\driverupdater\updater\amd64\driverrestore.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
1/30/2011 4:00:00 PM

Valid to:
1/30/2014 3:59:59 PM

Subject:
CN=Utililab GmbH, O=Utililab GmbH, STREET=Schumannstraße 17, L=Berlin, S=Berlin, PostalCode=10117, C=DE

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00B233BC32FCEFAC7A7B4F96557686C278

File PE Metadata
Compilation timestamp:
3/24/2005 5:42:19 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
1536:J6eEawgsMG3zfvaPAtT9zmEb3rlxHeWIC:JzAzfvaQT9zmU3rlxHeWIC

Entry address:
0x73D0

Entry point:
48, 83, EC, 58, 48, 89, 5C, 24, 70, 48, 89, 7C, 24, 78, 66, 81, 3D, 19, 8C, FF, FF, 4D, 5A, 74, 08, 33, DB, 89, 5C, 24, 60, EB, 7C, 48, 63, 05, 44, 8C, FF, FF, 48, 8D, 0D, 01, 8C, FF, FF, 48, 03, C1, 81, 38, 50, 45, 00, 00, 74, 08, 33, DB, 89, 5C, 24, 60, EB, 5B, 0F, B7, 48, 18, 81, F9, 0B, 01, 00, 00, 74, 32, 81, F9, 0B, 02, 00, 00, 74, 08, 33, DB, 89, 5C, 24, 60, EB, 3F, 83, B8, 84, 00, 00, 00, 0E, 77, 08, 33, DB, 89, 5C, 24, 60, EB, 2E, 33, DB, 39, 98, F8, 00, 00, 00, 0F, 95, C3, 89, 5C, 24, 60, EB, 1D...
 
[+]

Entropy:
5.3422

Code size:
31.5 KB (32,256 bytes)

Remove driverrestore.exe - Powered by Reason Core Security