ATGoViewerP.DLL

ATGoViewerP Module

TongYangOnline Co.,Ltd

The library ATGoViewerP.DLL has been detected as malware by 6 anti-virus scanners.
Publisher:
TongYangOnline Co.,Ltd  (signed and verified)

Product:
ATGoViewerP Module

Version:
1, 0, 0, 30

MD5:
83ad2f992b9807bac2733d7c98467479

SHA-1:
bbf3cb460e16263305f7ac31388f8d264d85ec13

SHA-256:
8f08fc6e9787f185062bdb1dacc4ddc3bcd18c8c97590886422eb3e3f9c1cd10

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
4/16/2024 11:54:43 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Agent.cada.3515
7.11.160.254

Comodo Security
UnclassifiedMalware
18866

IKARUS anti.virus
Trojan.Agent
t3scan.1.6.1.0

Norman
Suspicious_Gen2.QUFCL
11.20151016

Trend Micro House Call
Suspicious_GEN.F47V0711
7.2.289

VIPRE Antivirus
Trojan.Win32.Generic
31316

File size:
950.1 KB (972,872 bytes)

Product version:
1, 0, 0, 30

Copyright:
Copyright 2003

Original file name:
ATGoViewerP.DLL

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\windows\downloaded Program Files\atgoviewerp.dll

Digital Signature
Authority:
Thawte, Inc.

Valid from:
1/12/2011 4:00:00 PM

Valid to:
1/12/2013 3:59:59 PM

Subject:
CN="TongYangOnline Co.,Ltd", O="TongYangOnline Co.,Ltd", L=mapo, S=seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6B878F7DDB4F902D0CA77DBE510100D2

File PE Metadata
Compilation timestamp:
6/16/2008 10:26:53 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:mfXkIbf8sGETy+EILbMxurdN4VhJqfR1LohhID4aPkx5uC:HAyakPuC

Entry address:
0x2BAEC

Entry point:
55, 8B, EC, 53, 8B, 5D, 08, 56, 8B, 75, 0C, 57, 8B, 7D, 10, 85, F6, 75, 09, 83, 3D, 74, 03, 06, 10, 00, EB, 26, 83, FE, 01, 74, 05, 83, FE, 02, 75, 22, A1, DC, 1A, 06, 10, 85, C0, 74, 09, 57, 56, 53, FF, D0, 85, C0, 74, 0C, 57, 56, 53, E8, E7, FE, FF, FF, 85, C0, 75, 04, 33, C0, EB, 4E, 57, 56, 53, E8, 4A, 6D, FF, FF, 83, FE, 01, 89, 45, 0C, 75, 0C, 85, C0, 75, 37, 57, 50, 53, E8, C3, FE, FF, FF, 85, F6, 74, 05, 83, FE, 03, 75, 26, 57, 56, 53, E8, B2, FE, FF, FF, 85, C0, 75, 03, 21, 45, 0C, 83, 7D, 0C, 00...
 
[+]

Entropy:
6.5552

Developed / compiled with:
Microsoft Visual C++

Code size:
292 KB (299,008 bytes)

ActiveX Install
Name:
{D3C372F8-C26A-4304-A22D-2337C6CB9E62}


Remove ATGoViewerP.DLL - Powered by Reason Core Security