dpinst32.exe

Driver Package Installer (DPInst)

Dimension Engineering LLC

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable dpinst32.exe, “Driver Package Installer” has been detected as malware by 10 anti-virus scanners.
Publisher:
Microsoft Corporation  (signed by Dimension Engineering LLC)

Product:
Driver Package Installer (DPInst)

Description:
Driver Package Installer

Version:
2.1

MD5:
a7a7f8852261ffb2fdd39cd6d4ec31ad

SHA-1:
e0c5ad879ca640dfa856eecdbb48329dfa53e210

SHA-256:
50f89017ad3ecb57a29859fb3d8776f4ca4ed2c958fdaf3b95e5bdf4e7246415

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
11/17/2024 10:01:58 AM UTC  (today)

Scan engine
Detection
Engine version

F-Prot
W32/HLLP.41472
v6.4.6.5.141

herdProtect (fuzzy)
2015.9.12.20

K7 AntiVirus
Virus
13.170.9337

Malwarebytes
Trojan.Agent
v2015.09.12.08

McAfee
W32/HLLP.41472.e
5600.6644

MicroWorld eScan
Win32.Neshta.A
16.0.0.765

NANO AntiVirus
Virus.Win32.Neshta.cdby
0.26.0.53954

Norman
Neshta.C
11.20150912

nProtect
Virus/W32.Neshta
13.08.21.03

Quick Heal
W32.Neshta.A
9.15.12.00

File size:
898.6 KB (920,168 bytes)

Product version:
2.1

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
DPInst.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\evolv\escribe\drivers\usb serial\dpinst32.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/24/2012 6:55:41 AM

Valid to:
1/24/2013 6:55:41 AM

Subject:
CN=Dimension Engineering LLC, O=Dimension Engineering LLC, L=Akron, S=OH, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112199B3538735806151C4CFC5867CFB4656

File PE Metadata
Compilation timestamp:
5/23/2009 6:15:05 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:9ZtaKSpwmx5ATm/LC3fwf3OoU9xkYSr/mdBTRhKWIjsRP/1HHm/hHAM8i6r+LyIz:9ZxSpwmxvL/f3vCN1PMaLi6rAyIQjG

Entry address:
0x2116A

Entry point:
E8, 6C, 3C, 00, 00, E9, 1A, FE, FF, FF, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 5D, E9, 1D, 02, 00, 00, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 5D, E9, E5, FF, FF, FF, CC, CC, CC, CC, CC, 6A, 14, 68, A0, C0, 05, 01, E8, 5F, 1C, 00, 00, 83, 65, FC, 00, FF, 4D, 10, 78, 3A, 8B, 4D, 08, 2B, 4D, 0C, 89, 4D, 08, FF, 55, 14, EB, ED, 8B, 45, EC, 89, 45, E4, 8B, 45, E4, 8B, 00, 89, 45, E0, 8B, 45, E0, 81, 38, 63, 73, 6D, E0, 74, 0B, C7, 45, DC, 00, 00, 00, 00, 8B, 45, DC, C3, E8, 8C, 3C, 00, 00, 8B, 65, E8, C7, 45...
 
[+]

Entropy:
5.6935

Code size:
392 KB (401,408 bytes)

Remove dpinst32.exe - Powered by Reason Core Security