dpinst64.exe

Driver Package Installer (DPInst)

Chelsea Marketing LLC

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application dpinst64.exe, “Driver Package Installer” by Chelsea Marketing has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Chelsea Marketing LLC)

Product:
Driver Package Installer (DPInst)

Description:
Driver Package Installer

Version:
2.1

MD5:
e626deac3d2642b2fc377b8e7d74d163

SHA-1:
675aa899fdc49f2141bc04af2409f0672393c48e

SHA-256:
5e94e94cd7f3b30be6cce65d69d1fdde0e8601abd0ed6fcdada1e80bffd61c27

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 12:10:45 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win64.Generic
16.6.29.10

File size:
660.5 KB (676,360 bytes)

Product version:
2.1

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
DPInst.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\difx\f758db3fa44d78b9\dpinst64.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
11/3/2013 6:00:00 PM

Valid to:
11/4/2014 5:59:59 PM

Subject:
CN=Chelsea Marketing LLC, O=Chelsea Marketing LLC, L=Lawrence, S=New York, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
58049128CC0F5C55478DB1B59347D3E9

File PE Metadata
Compilation timestamp:
5/23/2009 5:37:17 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:7sW7OzpPId26dQcEaUrPvwgwkRVagRoOQTiHaQsVIhVLpHf2mmP:9IId79EaUTvwieMowXzZ2tP

Entry address:
0x5CBA8

Entry point:
48, 83, EC, 28, E8, 8F, 08, 00, 00, 48, 83, C4, 28, E9, D2, FC, FF, FF, CC, CC, CC, CC, CC, CC, FF, 25, 02, 4E, FA, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 3B, 0D, 51, 45, 02, 00, 75, 12, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 03, C2, 00, 00, 48, C1, C9, 10, E9, FC, 08, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, 48, 89, 5C, 24, 10, 44, 89, 44, 24, 18, 48, 89, 4C, 24, 08, 56, 57, 41, 54, 48, 83, EC, 40, 49, 8B, F1, 41, 8B, F8, 4C, 8B, E2...
 
[+]

Entropy:
5.9266

Code size:
510.5 KB (522,752 bytes)

Remove dpinst64.exe - Powered by Reason Core Security