driverrestore.exe

Windows Setup API

Utililab GmbH

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable driverrestore.exe, “Windows Setup API” has been detected as malware by 1 anti-virus scanner. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software.
Publisher:
Microsoft Corporation  (signed by Utililab GmbH)

Product:
Microsoft® Windows® Operating System

Description:
Windows Setup API

Version:
6.1.7600.16385 (win7_rtm.090713-1255)

MD5:
2b20a7bca7f07c2a09094fc24a3c2836

SHA-1:
17f7f8a4e01ecf6d82bae987d0469b28f4de6f90

SHA-256:
4e42b139b1f0415e1b8237924a707e18a1044b21d68f6fbd6bd896dafc914fec

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/26/2024 9:36:24 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Optional.Utililab.SystemOptimizer (L)
17.2.21.5

File size:
6.5 MB (6,774,784 bytes)

Product version:
6.1.7600.16385

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
SETUPAPI.DLL

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\utililab\systemoptimizer\updater\win7amd64\driverrestore.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
1/31/2011 8:00:00 AM

Valid to:
1/31/2014 7:59:59 AM

Subject:
CN=Utililab GmbH, O=Utililab GmbH, STREET=Schumannstraße 17, L=Berlin, S=Berlin, PostalCode=10117, C=DE

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00B233BC32FCEFAC7A7B4F96557686C278

File PE Metadata
Compilation timestamp:
7/14/2009 8:26:46 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
9.0

Entry address:
0x7310

Entry point:
48, 83, EC, 28, E8, 17, 03, 00, 00, 48, 83, C4, 28, E9, 62, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 3B, 0D, B9, 1D, 00, 00, 75, 12, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 03, C2, 00, 00, 48, C1, C9, 10, E9, 8C, 03, 00, 00, CC, CC, CC, CC, CC, CC, FF, 25, 3C, A0, FF, FF, CC, CC, CC, CC, CC, CC, FF, 25, 20, A0, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 40, 53, 48, 83, EC, 20, 45, 8B, 18, 48, 8B, DA, 4C, 8B, C9, 41...
 
[+]

Code size:
31.5 KB (32,256 bytes)

Remove driverrestore.exe - Powered by Reason Core Security