dgzdctkc.dll

浏览器安全模块

Changsha Spring Culture Communications Ltd.

The library dgzdctkc.dll, “浏览器安全模块(2014.03.14)” has been detected as malware by 20 anti-virus scanners.
Publisher:
HNSPRING  (signed by Changsha Spring Culture Communications Ltd.)

Product:
浏览器安全模块

Description:
浏览器安全模块(2014.03.14)

Version:
1.0

MD5:
bc7ee4d98bf3bd58598be266705f88b6

SHA-1:
cedc5835b0487f0a6208e9eebc956b717bcf2a4b

SHA-256:
4327efcc7ef601a4ba9041024834ab4f308d0e5a3375750d1ab40c594b719c4f

Scanner detections:
20 / 68

Status:
Malware

Analysis date:
4/23/2024 6:45:14 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.VMProtect
7.1.1

avast!
Win32:GenMaliciousA-ACB [Trj]
2014.9-160121

Bitdefender
Gen:Variant.Graftor.165424
1.0.20.105

Comodo Security
UnclassifiedMalware
22016

Emsisoft Anti-Malware
Gen:Variant.Graftor.165424
8.16.01.21.05

ESET NOD32
Win32/Packed.VMProtect.AAN (variant)
10.11581

Fortinet FortiGate
W32/FakeAV.OP!tr
1/21/2016

G Data
Gen:Variant.Graftor.165424
16.1.25

IKARUS anti.virus
Trojan.Win32.VMProtect
t3scan.1.8.9.0

K7 AntiVirus
Riskware
13.203.15813

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.781

McAfee
Artemis!BC7EE4D98BF3
5600.6513

NANO AntiVirus
Trojan.Win32.FakeAVOP.ctcwsl
0.30.24.1357

Norman
Suspicious_Gen4.GXVEF
11.20160121

Quick Heal
(Suspicious) - DNAScan
1.16.14.00

Sophos
Mal/FakeAV-OP
4.98

Trend Micro House Call
TROJ_GEN.R002C0ED615
7.2.21

Trend Micro
TROJ_GEN.R002C0ED615
10.465.21

VIPRE Antivirus
Trojan.Win32.Generic
39974

Zillya! Antivirus
Trojan.FakeAV.Win32.299849
2.0.0.2167

File size:
1.8 MB (1,881,992 bytes)

Product version:
1.0

Copyright:
版权所有 (C) 1996-2012年 浏览器安全模块

Original file name:
IESAFE.DLL

File type:
Dynamic link library (Win32 DLL)

Language:
Chinese (Simplified, PRC)

Common path:
C:\windows\dgzdctkc.dll

Digital Signature
Authority:
VeriSign, Inc.

Subject:
CN=Changsha Spring Culture Communications Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Changsha Spring Culture Communications Ltd., L=Changsha, S=Hunan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
55ECCB2274BCF4877B864F67ED1D1B49

File PE Metadata
Compilation timestamp:
3/14/2014 5:53:33 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:pXo+zbXf1ITZXkAmvFcoTtRJzfQw5x2VTw3t53qdGKGU4yPcaUe+8eBdPRBKwZaO:VrITZXkAqfz5QVTC5mH/+7BRHK+xd

Entry address:
0x20B2B

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, B1, 2D, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, B0, FE, 03, 10, 89, 0D, AC, FE, 03, 10, 89, 15, A8, FE, 03, 10, 89, 1D, A4, FE, 03, 10, 89, 35, A0, FE, 03, 10, 89, 3D, 9C, FE, 03, 10, 66, 8C, 15, C8, FE, 03, 10, 66, 8C, 0D, BC, FE, 03, 10, 66, 8C, 1D, 98, FE, 03, 10, 66, 8C, 05, 94, FE, 03, 10, 66, 8C, 25, 90, FE, 03, 10, 66, 8C, 2D, 8C, FE, 03, 10, 9C, 8F, 05, C0, FE...
 
[+]

Entropy:
6.7320

Code size:
198 KB (202,752 bytes)

Remove dgzdctkc.dll - Powered by Reason Core Security