d3dcompiler_47.dll

Direct3D HLSL Compiler for Redistribution

Lyoness Cashback AG

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The module d3dcompiler_47.dll, “Direct3D HLSL Compiler for Redistribution” by Lyoness Cashback AG has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Lyoness Cashback AG)

Product:
Microsoft® Windows® Operating System

Description:
Direct3D HLSL Compiler for Redistribution

Version:
6.3.9600.16384 (winblue_rtm.130821-1623)

MD5:
1206bb2d3500df39990700c7d6f0be39

SHA-1:
2062024b835039aeb2c90e510157b2ea16e234f7

SHA-256:
d21eb2041a44a069d078283323b85263efca3d8bc8bc123eda905badf8441021

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 10:28:20 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.LyonessCashbackAG (M)
16.1.13.21

File size:
3.3 MB (3,457,112 bytes)

Product version:
6.3.9600.16384

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
d3dcompiler_47.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\lyoness browser\application\42.0.2311.90\d3dcompiler_47.dll

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/21/2013 11:07:04 AM

Valid to:
10/21/2016 11:07:04 AM

Subject:
E=domainadmin@lyoness.ag, CN=Lyoness Cashback AG, O=Lyoness Cashback AG, L=Graz, S=Styria, C=AT

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121966E6F40865E27DA6418F77DA28077D3

File PE Metadata
Compilation timestamp:
8/21/2013 10:50:06 PM

OS version:
6.3

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

CTPH (ssdeep):
49152:AyZ9lnpmVm/w+EwVOmufvkQS8MH2J9CqS5Sqr88pPWW5KhQYPsXqUiQS:R9fWAwVBC8MH2JNSF8+YPsXqUTS

Entry address:
0x30E737

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, D1, 08, 00, 00, 5D, E9, 2A, 00, 00, 00, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, B8, 63, 73, 6D, E0, 39, 45, 08, 75, 0D, FF, 75, 0C, 50, E8, 36, 07, 00, 00, 59, 59, 5D, C3, 33, C0, 5D, C3, CC, CC, CC, CC, CC, 6A, 2C, 68, B8, 8F, 31, 10, E8, 49, 09, 00, 00, C7, 45, E4, 01, 00, 00, 00, 33, F6, 89, 75, FC, 8B, 45, 0C, 83, F8, 01, 77, 05, A3, 00, A0, 31, 10, 83, 7D, 0C, 00, 75, 11, 83, 3D, 40, FC, 31, 10, 00, 75, 08, 89, 75, E4, E9, 1E, 02, 00, 00, 8B, 45, 0C, 83...
 
[+]

Entropy:
6.4389

Code size:
3.1 MB (3,245,568 bytes)

Remove d3dcompiler_47.dll - Powered by Reason Core Security