driverrestore.exe

Windows Setup API

Utililab GmbH

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable driverrestore.exe, “Windows Setup API” has been detected as malware by 1 anti-virus scanner.
Publisher:
Microsoft Corporation  (signed by Utililab GmbH)

Product:
Microsoft® Windows® Operating System

Description:
Windows Setup API

Version:
5.2.3718.0 (dnsrv.021114-1947)

MD5:
3b85d66a39f84d2544f5432dc21b6fed

SHA-1:
35c8b6753f7dfed4c939a2cc98748eec30e6d9b2

SHA-256:
94ebed09929bb1ee798a88933557c73014f85eeeaf12701a588e22f94467245b

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/26/2024 9:45:44 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Optional.Utililab.SystemOptimizer (L)
17.1.20.22

File size:
59.2 KB (60,592 bytes)

Product version:
5.2.3718.0

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
SETUPAPI.DLL

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\utililab\systemoptimizer\updater\xp\driverrestore.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
1/31/2011 3:30:00 AM

Valid to:
1/31/2014 3:29:59 AM

Subject:
CN=Utililab GmbH, O=Utililab GmbH, STREET=Schumannstraße 17, L=Berlin, S=Berlin, PostalCode=10117, C=DE

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00B233BC32FCEFAC7A7B4F96557686C278

File PE Metadata
Compilation timestamp:
11/15/2002 10:02:05 AM

OS version:
5.2

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
7.10

Entry address:
0x5211

Entry point:
6A, 28, 68, C8, 15, 00, 01, E8, F3, 01, 00, 00, 66, 81, 3D, 00, 00, 00, 01, 4D, 5A, 75, 28, A1, 3C, 00, 00, 01, 81, B8, 00, 00, 00, 01, 50, 45, 00, 00, 75, 17, 0F, B7, 88, 18, 00, 00, 01, 81, F9, 0B, 01, 00, 00, 74, 21, 81, F9, 0B, 02, 00, 00, 74, 06, 83, 65, E4, 00, EB, 2A, 83, B8, 84, 00, 00, 01, 0E, 76, F1, 33, C9, 39, 88, F8, 00, 00, 01, EB, 11, 83, B8, 74, 00, 00, 01, 0E, 76, DE, 33, C9, 39, 88, E8, 00, 00, 01, 0F, 95, C1, 89, 4D, E4, 83, 65, FC, 00, 6A, 01, FF, 15, 7C, 11, 00, 01, 59, 83, 0D, CC, 61...
 
[+]

Entropy:
5.2329

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
20 KB (20,480 bytes)

Remove driverrestore.exe - Powered by Reason Core Security