FlyVPNBind.dll

FlyVPN

FlyVPN INC

It is installed as a Winsock Layered Service Provider (LSP) named “FlyVPN Bind UDP Filter” as a layered chain entry. This is installed with FlyVPN.
Publisher:
www.flyvpn.com  (signed by FlyVPN INC)

Product:
FlyVPN

Description:
FlyVPN Windows Socket Provider

Version:
2.2.3.8

MD5:
8621d6619d7186f3f68ac050844e31d8

SHA-1:
2becb2a004e079e127685d6e34f98f5163497043

SHA-256:
36a2c4b022430c068d2ce38ad52f1b10fdb887fa26943f7ec77096200ece9499

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/18/2017 1:34:04 PM UTC  (today)

File size:
167.1 KB (171,128 bytes)

Product version:
2.2.3.8

Copyright:
Copyright (C) 2009 - 2012 www.flyvpn.com. All rights reserved.

Original file name:
FlyVPNBind.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\flyvpn\flyvpnbind.dll

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/8/2012 3:16:43 PM

Valid to:
2/8/2015 3:16:43 PM

Subject:
CN=FlyVPN INC, O=FlyVPN INC, L=Shanghai, S=Shanghai, C=CN

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11214C547F499517FD0797F799C5A1C553CB

File PE Metadata
Compilation timestamp:
11/6/2012 8:03:32 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:ieL4iXWhIPPBxTHihDdg0YgneYvdgn8kN5PgPlO:iM4iXWhInbOhDqls8nTPWO

Entry address:
0x12044

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 7E, 89, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, 68, D0, 20, 01, 10, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 5C, 61, 02, 10, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, CC, CC, CC...
 
[+]

Entropy:
6.4082

Code size:
124 KB (126,976 bytes)

Winsock2 LSP
Name:
FlyVPN Bind UDP Filter

Type:
Layered Chain Entry

Provider ID:
{4DE028BC-6CDD-462E-A8A5-6DDF42D4D404}

Service flags:
0x20609


The file FlyVPNBind.dll has been discovered within the following program.

FlyVPN  by FlyVPN Inc.
Publisher's description - “VPN allows you to change your region, unlock online game limitation, Bypass Internet restrictions such as school, company and hotel, reduce lag for online game, unblock websites, anonymous web browsing, Anonymous surfing, hide & change IP.”
www.flyvpn.com
About 1% of users remove it
 
Powered by Should I Remove It?

Scan FlyVPNBind.dll - Powered by Reason Core Security