driverrestore.exe

Windows Setup API

Utililab GmbH

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable driverrestore.exe, “Windows Setup API” has been detected as malware by 1 anti-virus scanner. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
Microsoft Corporation  (signed by Utililab GmbH)

Product:
Microsoft® Windows® Operating System

Description:
Windows Setup API

Version:
5.2.3790.1830 (srv03_sp1_rtm.050324-1447)

MD5:
6137d54efba987764f5b1e4b2a0c6aee

SHA-1:
ef4b4e81ceebb3d7bb9b5a9a6b50cdedc0560f2b

SHA-256:
485fa3b378a136cbbdbb95cac15772ecc67cd87f67deb50db3cc2cbafa192bc3

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/26/2024 9:31:51 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Optional.Utililab.SystemOptimizer (L)
17.2.21.5

File size:
4.3 MB (4,534,272 bytes)

Product version:
5.2.3790.1830

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
SETUPAPI.DLL

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\utililab\systemoptimizer\updater\amd64\driverrestore.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
1/31/2011 8:00:00 AM

Valid to:
1/31/2014 7:59:59 AM

Subject:
CN=Utililab GmbH, O=Utililab GmbH, STREET=Schumannstraße 17, L=Berlin, S=Berlin, PostalCode=10117, C=DE

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00B233BC32FCEFAC7A7B4F96557686C278

File PE Metadata
Compilation timestamp:
3/25/2005 8:42:19 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
8.0

Entry address:
0x73D0

Entry point:
48, 83, EC, 58, 48, 89, 5C, 24, 70, 48, 89, 7C, 24, 78, 66, 81, 3D, 19, 8C, FF, FF, 4D, 5A, 74, 08, 33, DB, 89, 5C, 24, 60, EB, 7C, 48, 63, 05, 44, 8C, FF, FF, 48, 8D, 0D, 01, 8C, FF, FF, 48, 03, C1, 81, 38, 50, 45, 00, 00, 74, 08, 33, DB, 89, 5C, 24, 60, EB, 5B, 0F, B7, 48, 18, 81, F9, 0B, 01, 00, 00, 74, 32, 81, F9, 0B, 02, 00, 00, 74, 08, 33, DB, 89, 5C, 24, 60, EB, 3F, 83, B8, 84, 00, 00, 00, 0E, 77, 08, 33, DB, 89, 5C, 24, 60, EB, 2E, 33, DB, 39, 98, F8, 00, 00, 00, 0F, 95, C3, 89, 5C, 24, 60, EB, 1D...
 
[+]

Code size:
31.5 KB (32,256 bytes)

Remove driverrestore.exe - Powered by Reason Core Security