fvsvpgk.dll

浏览器安全模块

Changsha Spring Culture Communications Ltd.

The library fvsvpgk.dll, “浏览器安全模块(2014.07.25)” has been detected as malware by 13 anti-virus scanners.
Publisher:
HNSPRING  (signed by Changsha Spring Culture Communications Ltd.)

Product:
浏览器安全模块

Description:
浏览器安全模块(2014.07.25)

Version:
1.0

MD5:
705a8ebb62c65624c85913852457eaf7

SHA-1:
fc72d13e19ced3907fcc40f26cf0ff8efc91ce90

SHA-256:
7162fb0145509facee273b723b7ea221a65d0df48544b1f4e144b03c556bbad1

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
4/19/2024 8:28:06 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:GenMaliciousA-ACB [Trj]
2014.9-160203

Comodo Security
UnclassifiedMalware
21297

ESET NOD32
Win32/Packed.VMProtect.AAN (variant)
10.11271

Fortinet FortiGate
W32/FakeAV.OP!tr
2/3/2016

IKARUS anti.virus
Trojan.Win32.VMProtect
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.200.15159

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.716

McAfee
Artemis!705A8EBB62C6
5600.6500

Norman
Suspicious_Gen4.GZADM
11.20160203

Panda Antivirus
Trj/Chgt.D
16.02.03.07

Quick Heal
(Suspicious) - DNAScan
2.16.14.00

Sophos
Mal/FakeAV-OP
4.98

VIPRE Antivirus
Trojan.Win32.Generic
38130

File size:
1.9 MB (1,945,480 bytes)

Product version:
1.0

Copyright:
版权所有 (C) 1996-2012年 浏览器安全模块

Original file name:
IESAFE.DLL

File type:
Dynamic link library (Win32 DLL)

Language:
Chinese (Simplified, PRC)

Common path:
C:\windows\fvsvpgk.dll

Digital Signature
Authority:
VeriSign, Inc.

Subject:
CN=Changsha Spring Culture Communications Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Changsha Spring Culture Communications Ltd., L=Changsha, S=Hunan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
55ECCB2274BCF4877B864F67ED1D1B49

File PE Metadata
Compilation timestamp:
7/25/2014 4:01:30 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:WMKHEPQEySCaTKwRlAmvFco2RdczfQw5x2Vn72CftU4yPcFClVHktLV0bnHb5D16:1mSCaThRlAhefz5QVy5jlAibn75Q

Entry address:
0x22A3B

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 41, 30, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 10, 2F, 04, 10, 89, 0D, 0C, 2F, 04, 10, 89, 15, 08, 2F, 04, 10, 89, 1D, 04, 2F, 04, 10, 89, 35, 00, 2F, 04, 10, 89, 3D, FC, 2E, 04, 10, 66, 8C, 15, 28, 2F, 04, 10, 66, 8C, 0D, 1C, 2F, 04, 10, 66, 8C, 1D, F8, 2E, 04, 10, 66, 8C, 05, F4, 2E, 04, 10, 66, 8C, 25, F0, 2E, 04, 10, 66, 8C, 2D, EC, 2E, 04, 10, 9C, 8F, 05, 20, 2F...
 
[+]

Entropy:
6.7503

Code size:
205.5 KB (210,432 bytes)

Remove fvsvpgk.dll - Powered by Reason Core Security