dpinst_64.exe

Установщик пакетов драйверов (DPInst)

Atom Security OOO

The application dpinst_64.exe, “Установщик пакетов драйверов” by Atom Security OOO has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Корпорация Майкрософт  (signed by Atom Security OOO)

Product:
Установщик пакетов драйверов (DPInst)

Description:
Установщик пакетов драйверов

Version:
2.1

MD5:
79a3b531eb73ff8ff6ed6e4bafcc6aa2

SHA-1:
6e20fec0ac59d50e18d62f9b927bc2b6130a9436

SHA-256:
8b80380382485ffeb6c955ecd3a5ca46e6aeade2a9e01345ca2fff9aa3b5d01b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/28/2024 4:49:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.AtomSecu
16.9.30.22

File size:
1022 KB (1,046,488 bytes)

Product version:
2.1

Copyright:
(С) Корпорация Майкрософт. Все права защищены.

Original file name:
DPInst.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\difx\de9beb9f70d26d08\dpinst_64.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/24/2013 3:00:00 AM

Valid to:
6/25/2014 2:59:59 AM

Subject:
CN=Atom Security OOO, OU=development, O=Atom Security OOO, STREET="Academician Koptyuga Prospect, 4,office 158", L=Novosibirsk, S=nso, PostalCode=630090, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
717783EFCF5E8A80B86D166EFF5E6862

File PE Metadata
Compilation timestamp:
5/23/2009 1:37:17 PM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:9sSOzpPId26dQcEaUrPvwgwkRVagRoDHTj8K1sqI6VLp4XOigSbduP/1HHm/hHAR:PIId79EaUTvwieMozMEcOigSpuPMaLig

Entry address:
0x5CBA8

Entry point:
48, 83, EC, 28, E8, 8F, 08, 00, 00, 48, 83, C4, 28, E9, D2, FC, FF, FF, CC, CC, CC, CC, CC, CC, FF, 25, 02, 4E, FA, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 3B, 0D, 51, 45, 02, 00, 75, 12, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 03, C2, 00, 00, 48, C1, C9, 10, E9, FC, 08, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, 48, 89, 5C, 24, 10, 44, 89, 44, 24, 18, 48, 89, 4C, 24, 08, 56, 57, 41, 54, 48, 83, EC, 40, 49, 8B, F1, 41, 8B, F8, 4C, 8B, E2...
 
[+]

Code size:
510.5 KB (522,752 bytes)

Remove dpinst_64.exe - Powered by Reason Core Security