IESAFE.DLL

浏览器安全模块

Changsha Spring Culture Communications Ltd.

The library IESAFE.DLL, “浏览器安全模块(2014.07.02)” has been detected as malware by 7 anti-virus scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘’.
Publisher:
HNSPRING  (signed by Changsha Spring Culture Communications Ltd.)

Product:
浏览器安全模块

Description:
浏览器安全模块(2014.07.02)

Version:
1.0

MD5:
03712cba2829b9c9b5593a938cbfc3a7

SHA-1:
b90d6b1f4e8a146715dac7a967accd67c2de698c

SHA-256:
6b766fad4f4da116ee227b1dde78752f5f7b07a6475d1ee2dae315dbd458ea92

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/19/2024 9:31:11 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Fakealert.59424
211

ESET NOD32
Win32/Packed.VMProtect.AAN (variant)
10.10239

F-Secure
Trojan.Fakealert.59424
11.2016-07-07_5

MicroWorld eScan
Trojan.Fakealert.59424
17.0.0.567

Panda Antivirus
Trj/Thed.W
16.07.07.07

Quick Heal
(Suspicious) - DNAScan
7.16.14.00

Sophos
Mal/FakeAV-OP
4.98

File size:
1.8 MB (1,930,120 bytes)

Product version:
1.0

Copyright:
版权所有 (C) 1996-2012年 浏览器安全模块

Original file name:
IESAFE.DLL

File type:
Dynamic link library (Win32 DLL)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/1/2012 8:00:00 AM

Valid to:
11/1/2015 7:59:59 AM

Subject:
CN=Changsha Spring Culture Communications Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Changsha Spring Culture Communications Ltd., L=Changsha, S=Hunan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
55ECCB2274BCF4877B864F67ED1D1B49

File PE Metadata
Compilation timestamp:
7/2/2014 7:33:21 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:y9mOmjUEC4/xOpT/RlAmvFcoURWCzfQw5x2VL723fiU4yPcfIKkWLP7gJ0Xvv8DY:+nsspT/RlALlfz5QV+ZMkePsCvvoK

Entry address:
0x224AB

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 41, 30, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 10, 1F, 04, 10, 89, 0D, 0C, 1F, 04, 10, 89, 15, 08, 1F, 04, 10, 89, 1D, 04, 1F, 04, 10, 89, 35, 00, 1F, 04, 10, 89, 3D, FC, 1E, 04, 10, 66, 8C, 15, 28, 1F, 04, 10, 66, 8C, 0D, 1C, 1F, 04, 10, 66, 8C, 1D, F8, 1E, 04, 10, 66, 8C, 05, F4, 1E, 04, 10, 66, 8C, 25, F0, 1E, 04, 10, 66, 8C, 2D, EC, 1E, 04, 10, 9C, 8F, 05, 20, 1F...
 
[+]

Entropy:
6.7399

Code size:
204 KB (208,896 bytes)

Internet Explorer BHO
CLSID:
{CAD5567A-C3E8-4CCE-AC64-70B29D20E151}


Remove IESAFE.DLL - Powered by Reason Core Security