CurXP0.dll

CursorFX

Stardock Systems Inc

The library CurXP0.dll, “CursorFX support DLL” has been detected as malware by 4 anti-virus scanners.
Publisher:
Stardock Systems Inc  (signed and verified)

Product:
CursorFX

Description:
CursorFX support DLL

Version:
2, 0, 0, 1

MD5:
dc1788b2c07538f07b5f84c5923d3c0c

SHA-1:
800a45578560dbbe9f30c2dbd6fbce8e5293bb79

SHA-256:
9dc610c398088681982730e732ad03647588f0bc72f00491658bd87db095ab7f

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
4/18/2024 11:40:53 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AVG
Win32/Floxif.A
2013.0.4477

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.15.154

File size:
110.8 KB (113,423 bytes)

Product version:
2, 0, 0, 1

Copyright:
Copyright © 2001-2007 RiccioSoft, Copyright © 2001-2007 Stardock Corporation

Original file name:
CurXP0.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\stardock\cursorfx\curxp0.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/18/2007 6:00:00 AM

Valid to:
9/18/2009 5:59:59 AM

Subject:
CN=Stardock Systems Inc, OU=Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Stardock Systems Inc, L=Plymouth, S=Michigan, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
47E53E5A58610897FCDA0DC227E2A44D

File PE Metadata
Compilation timestamp:
2/1/2008 3:21:00 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:t87+9HMIRT8yeZFgTN2s+zheW6BVrqzCJ3bdDY+W14N4NmzWlIA7hKRQCuq2M:tND8yeO2lQBV+UdE+rECWp7hKp

Entry address:
0x17E0

Entry point:
E9, 9F, 22, 00, 00, 45, 0C, 89, 45, FC, 83, 7D, FC, 00, 74, 20, 83, 7D, FC, 01, 74, 05, E9, 93, 00, 00, 00, 8B, 4D, 08, 89, 0D, 2C, 80, 00, 10, 8B, 55, 08, 52, FF, 15, 30, 70, 00, 10, EB, 7E, 83, 3D, 34, 80, 00, 10, 00, 74, 75, C7, 05, 34, 80, 00, 10, 00, 00, 00, 00, 83, 3D, 1C, 80, 00, 10, 00, 74, 0E, A1, 1C, 80, 00, 10, 50, E8, 09, 01, 00, 00, 83, C4, 04, 83, 3D, 20, 80, 00, 10, 00, 74, 0F, 8B, 0D, 20, 80, 00, 10, 51, E8, F1, 00, 00, 00, 83, C4, 04, 83, 3D, 28, 80, 00, 10, 00, 74, 0F, 8B, 15, 55, 8B, EC...
 
[+]

Entropy:
7.4791

Packer / compiler:
Xtreme-Protector v1.05

Code size:
21 KB (21,504 bytes)

Remove CurXP0.dll - Powered by Reason Core Security