hxdnotify.dll

hxdnotify

NetZone Info-Tech Co., Ltd., Shanghai

The module hxdnotify.dll by NetZone Info-Tech Co.,, Shanghai has been detected as a potentially unwanted program by 22 anti-malware scanners.
Publisher:
Netzonesoft Corp.  (signed by NetZone Info-Tech Co., Ltd., Shanghai)

Product:
hxdnotify

Version:
3.0.2900

MD5:
f80c3461540e46f5f369e66376030f4e

SHA-1:
ae748b249e831ce6bbf1473478731602be624f5d

Scanner detections:
22 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 4:48:53 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.8410837
517

Agnitum Outpost
Trojan.Agent2
7.1.1

Avira AntiVirus
TR/Agent.620816
7.11.214.140

avast!
Win32:Malware-gen
2014.9-150905

AVG
Agent2
2016.0.2995

Bitdefender
Trojan.Generic.8410837
1.0.20.1240

Comodo Security
TrojWare.Win32.Agent.fjzx
21319

Dr.Web
BackDoor.Infector.50
9.0.1.0248

Emsisoft Anti-Malware
Trojan.Generic.8410837
8.15.09.05.04

Fortinet FortiGate
Dx.C2Q!tr
9/5/2015

F-Secure
Trojan.Generic.8410837
11.2015-05-09_7

G Data
Trojan.Generic.8410837
15.9.25

IKARUS anti.virus
Trojan.Win32.Agent
t3scan.1.8.6.0

McAfee
Artemis!F80C3461540E
5600.6651

MicroWorld eScan
Trojan.Generic.8410837
16.0.0.744

NANO AntiVirus
Trojan.Win32.Agent.gwbcv
0.30.0.296

nProtect
Trojan.Generic.8410837
15.03.06.01

Panda Antivirus
Trj/CI.A
15.09.05.04

Reason Heuristics
PUP.Optional.NetZoneInfoTechCoShanghai
15.9.5.16

Rising Antivirus
PE:Trojan.Win32.Generic.1251C8F0!307349744
23.00.65.15903

Vba32 AntiVirus
Trojan.Agent
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
38194

File size:
606.3 KB (620,816 bytes)

Product version:
3.0.2900

Copyright:
Copyright (C) Netzonesoft Corp. 2008-2009

Original file name:
hxdnotify

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Windows\System32\hxdnotify.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/26/2011 8:00:00 AM

Valid to:
8/5/2012 7:59:59 AM

Subject:
CN="NetZone Info-Tech Co., Ltd., Shanghai", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="NetZone Info-Tech Co., Ltd., Shanghai", L=Shanghai, S=Shanghai, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
00F1D32C1B972DF4D97FEF5EE83B90E5

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:ksH5FFRWejjVZcA5v5kOM+oCaDZ/6dlGo5athnxPMg6:1ZB3ZcArEf+GVtBqg6

Entry address:
0x73504

Entry point:
55, 8B, EC, 83, C4, C4, B8, 54, 31, 47, 00, E8, 10, 2D, F9, FF, E8, 27, 0B, F9, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5516

Developed / compiled with:
Microsoft Visual C++

Code size:
457.5 KB (468,480 bytes)

Startup Files Notify
Name:
hxdNotify


Remove hxdnotify.dll - Powered by Reason Core Security