gboxweb.dll

WebRuner Module

Beijing Leeuu Technology Ltd.

Publisher:
www.leeuu.com  (signed by Beijing Leeuu Technology Ltd.)

Product:
WebRuner Module

Version:
1, 0, 0, 5

MD5:
9c0c8c180d0c9a1521d5cce1516c951e

SHA-1:
725db14ee1af12b005be9ead28acb05b331b2202

SHA-256:
8232fd1e63fda4bc0a6e2eb715eb321d8ea74629749babf1a0d162ffd012657c

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/24/2024 10:36:30 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Agent-ANZG [Trj]
2014.9-160109

G Data
Win32:Agent-ANZG
16.1.22

File size:
141.9 KB (145,280 bytes)

Product version:
1, 0, 0, 5

Copyright:
Copyright 2011

Original file name:
WebRuner.DLL

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\roaming\gboxweb.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/24/2010 8:00:00 AM

Valid to:
11/20/2013 7:59:59 AM

Subject:
CN=Beijing Leeuu Technology Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Beijing Leeuu Technology Ltd., L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
30B3EA7DC55CCA67BEEB9BBBA6EB8BCC

File PE Metadata
Compilation timestamp:
3/8/2011 3:42:26 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:vuGXPJh4vtl799EcWAgoDYfKIg9oMR2pqrA:vBfoTgosfiP4EE

Entry address:
0x105D

Entry point:
FF, 74, 24, 0C, FF, 74, 24, 0C, FF, 74, 24, 0C, E8, E4, 13, 00, 00, C2, 0C, 00, FF, 15, 04, 51, 01, 10, 33, C0, C3, A1, 38, D7, 01, 10, 56, 85, C0, 75, 13, FF, 74, 24, 08, 50, FF, 35, D8, D6, 01, 10, FF, 15, 2C, 51, 01, 10, 5E, C3, 8B, 0D, 3C, D7, 01, 10, 8B, 15, 34, D7, 01, 10, FF, 05, 3C, D7, 01, 10, 23, D1, 8B, 34, 90, 8B, 44, 24, 08, 83, C0, 08, 50, 6A, 00, 56, FF, 15, 2C, 51, 01, 10, 85, C0, 74, 07, 89, 30, 83, C0, 08, 5E, C3, 33, C0, 5E, C3, 8B, 44, 24, 04, 0F, AF, 44, 24, 08, 50, E8, 9D, FF, FF, FF...
 
[+]

Entropy:
5.7564

Code size:
80 KB (81,920 bytes)

Scan gboxweb.dll - Powered by Reason Core Security