driverrestore.exe

Windows Setup API

Software Marketing Ltd

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application driverrestore.exe, “Windows Setup API” by Software Marketing has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software.
Publisher:
Microsoft Corporation  (signed by Software Marketing Ltd)

Product:
Microsoft® Windows® Operating System

Description:
Windows Setup API

Version:
6.1.7600.16385 (win7_rtm.090713-1255)

MD5:
c04587e970623e20f6d541b652197cef

SHA-1:
585de1e2e225f2460aa809e0962049617acc23ee

SHA-256:
f80d4dc38b28de6e740d97dbf6d9346de7597df4c50840f4b452768e3f8bdab8

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
2/25/2025 3:57:23 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SoftwareMarketing.Installer.Meta (L)
16.1.22.8

File size:
85.5 KB (87,552 bytes)

Product version:
6.1.7600.16385

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
SETUPAPI.DLL

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ultra pc care\updater\win7amd64\driverrestore.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
6/14/2011 2:59:41 AM

Valid to:
6/14/2013 2:59:41 AM

Subject:
CN=Software Marketing Ltd, O=Software Marketing Ltd, L=Hong Kong, S=HK, C=HK

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B74A3CB7B3F71

File PE Metadata
Compilation timestamp:
7/14/2009 1:26:46 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
1536:fPM0pa0WfEYp9Y/XQhpgnbP212YCQpDRiF4O7WaLHL:ftOYe4bu1TpDR8RWKL

Entry address:
0x7310

Entry point:
48, 83, EC, 28, E8, 17, 03, 00, 00, 48, 83, C4, 28, E9, 62, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 3B, 0D, B9, 1D, 00, 00, 75, 12, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 03, C2, 00, 00, 48, C1, C9, 10, E9, 8C, 03, 00, 00, CC, CC, CC, CC, CC, CC, FF, 25, 3C, A0, FF, FF, CC, CC, CC, CC, CC, CC, FF, 25, 20, A0, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 40, 53, 48, 83, EC, 20, 45, 8B, 18, 48, 8B, DA, 4C, 8B, C9, 41...
 
[+]

Code size:
31.5 KB (32,256 bytes)

Remove driverrestore.exe - Powered by Reason Core Security