libcurl.dll

The cURL library

DriverDevelop.com

libcurl.dll is the cURL library (libcurl) used for transferring data with URL syntax including HTTP. This library is used to plug into C-based applictaions and is recompiled by DriverDevelop.com. The module libcurl.dll, “libcurl Shared Library” by DriverDevelop.com has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. Note, this is a common distributed file and although it has been detected it might not be a threat is un-coupled from its distribution source.
Publisher:
The cURL library, http://curl.haxx.se/  (signed by DriverDevelop.com)

Product:
The cURL library

Description:
libcurl Shared Library

Version:
7.21.3

MD5:
5b9f0b75f2c554a566058c287d667170

SHA-1:
1bd15f4a50c33e396cfce4d7601610616f2689da

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
This is the cURL library (libcurl) used for transferring data with URL syntax including HTTP. This library is used to plug into C-based applictaions. While the file itself is not dangerous, it is part of a program that has been detected.

Analysis date:
7/3/2025 1:35:36 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.18.7

File size:
246.5 KB (252,408 bytes)

Product version:
7.21.3

Copyright:
?1996 - 2010 Daniel Stenberg, <daniel@haxx.se>.

Original file name:
libcurl.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\kingsoft\klive business\libcurl.dll

Digital Signature
Authority:
DriverDevelop.com

Valid from:
8/15/2009 11:02:01 AM

Valid to:
8/13/2019 11:02:01 AM

Subject:
E=ca@zndev.com, CN=DriverDevelop.com Signtools Test cert, OU=Dept. CodeSign CA, O=DriverDevelop.com, S=BeiJing, C=CN

Issuer:
E=ca@zndev.com, CN=DriverDevelop.com CA, OU=DriverDevelop.com CA, O=DriverDevelop.com, L=BeiJing, S=BeiJing, C=CN

Serial number:
011E

File PE Metadata
Compilation timestamp:
1/14/2011 12:25:53 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x30A99

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 55, 04, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, CC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, E0, A2, 03, 10, 89, 0D, DC, A2, 03, 10, 89, 15, D8, A2, 03, 10, 89, 1D, D4, A2, 03, 10, 89, 35, D0, A2, 03, 10, 89, 3D, CC, A2, 03, 10, 66, 8C, 15, F8, A2, 03, 10, 66, 8C, 0D, EC, A2, 03, 10, 66, 8C, 1D, C8, A2, 03, 10, 66, 8C, 05, C4, A2, 03, 10, 66, 8C, 25, C0, A2, 03, 10, 66, 8C, 2D, BC, A2, 03, 10, 9C, 8F, 05, F0, A2...
 
[+]

Entropy:
6.6386

Code size:
192 KB (196,608 bytes)

Remove libcurl.dll - Powered by Reason Core Security