driverrestore.exe

Windows Setup API

Utililab GmbH

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable driverrestore.exe, “Windows Setup API” has been detected as malware by 1 anti-virus scanner.
Publisher:
Microsoft Corporation  (signed by Utililab GmbH)

Product:
Microsoft® Windows® Operating System

Description:
Windows Setup API

Version:
5.2.3718.0 (dnsrv.021114-1947)

MD5:
986f43b4c5f3f0d59154d6bc9b104896

SHA-1:
2ee2310d89ea0a4618a4871d35f52baf2df5625c

SHA-256:
99562ec0321141f64a650b93a222cdc0775846435c88502e47773431deb074e0

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/26/2024 9:51:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Optional.Utililab.SystemOptimizer (L)
17.2.17.20

File size:
59.2 KB (60,592 bytes)

Product version:
5.2.3718.0

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
SETUPAPI.DLL

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\utililab\systemoptimizer\updater\xp\driverrestore.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
1/31/2011 8:00:00 AM

Valid to:
1/31/2014 7:59:59 AM

Subject:
CN=Utililab GmbH, O=Utililab GmbH, STREET=Schumannstraße 17, L=Berlin, S=Berlin, PostalCode=10117, C=DE

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00B233BC32FCEFAC7A7B4F96557686C278

File PE Metadata
Compilation timestamp:
11/15/2002 2:32:05 PM

OS version:
5.2

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
7.10

Entry address:
0x5211

Entry point:
6A, 28, 68, C8, 15, 00, 01, E8, F3, 01, 00, 00, 66, 81, 3D, 00, 00, 00, 01, 4D, 5A, 75, 28, A1, 3C, 00, 00, 01, 81, B8, 00, 00, 00, 01, 50, 45, 00, 00, 75, 17, 0F, B7, 88, 18, 00, 00, 01, 81, F9, 0B, 01, 00, 00, 74, 21, 81, F9, 0B, 02, 00, 00, 74, 06, 83, 65, E4, 00, EB, 2A, 83, B8, 84, 00, 00, 01, 0E, 76, F1, 33, C9, 39, 88, F8, 00, 00, 01, EB, 11, 83, B8, 74, 00, 00, 01, 0E, 76, DE, 33, C9, 39, 88, E8, 00, 00, 01, 0F, 95, C1, 89, 4D, E4, 83, 65, FC, 00, 6A, 01, FF, 15, 7C, 11, 00, 01, 59, 83, 0D, CC, 61...
 
[+]

Entropy:
5.2329

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
20 KB (20,480 bytes)

Remove driverrestore.exe - Powered by Reason Core Security