Microsoft.DirectX.AudioVideoPlayback.dll

Microsoft DirectX for Windows

Iminent

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The module Microsoft.DirectX.AudioVideoPlayback.dll, “Microsoft Managed AudioVideoPlayback” by Iminent has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Iminent)

Product:
Microsoft® DirectX for Windows®

Description:
Microsoft Managed AudioVideoPlayback

Version:
5.04.00.2904

MD5:
37f520cd72b55dc0c19a329019ca63f8

SHA-1:
f08babeebd207c2bc22e116300533f8039c313e2

SHA-256:
ae7f2e025341525b39c99749e83d4a29c9fdf2b7ad4a9b4ff862e417bf1dcdb5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 7:43:33 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien.Iminent (M)
16.2.12.8

File size:
58 KB (59,368 bytes)

Product version:
5.04.00.2904

Copyright:
Copyright © Microsoft Corporation. All rights reserved.

Original file name:
Microsoft.DirectX.AudioVideoPlayback.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\iminent\microsoft.directx.audiovideoplayback.dll

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/26/2010 4:31:06 PM

Valid to:
1/27/2012 4:31:03 PM

Subject:
CN=Iminent, O=Iminent, L=Paris, S=France, C=FR

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001266AC7D81A

File PE Metadata
Compilation timestamp:
7/9/2004 7:06:56 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:HBJPuUm+QFYqG9se2k5R7vtv8+80t2TxJNdfr83A/E9t3DAsmRLYZ:zu8qYqK6k5R7O+80tKxJN983aErmRE

Entry address:
0xCC0C

Entry point:
FF, 25, 48, 10, 40, 00, CC, CC, CC, CC, CC, CC, FF, 25, 20, 10, 40, 00, CC, CC, CC, CC, CC, CC, FF, 25, 1C, 10, 40, 00, CC, CC, CC, CC, CC, CC, FF, 25, 18, 10, 40, 00, CC, CC, CC, CC, CC, CC, FF, 25, 24, 10, 40, 00, CC, CC, CC, CC, CC, CC, FF, 25, 58, 10, 40, 00, CC, CC, CC, CC, CC, CC, FF, 25, 54, 10, 40, 00, CC, CC, CC, CC, CC, CC, FF, 25, 50, 10, 40, 00, CC, CC, CC, CC, CC, CC, FF, 25, 30, 10, 40, 00, CC, CC, CC, CC, CC, CC, FF, 25, 34, 10, 40, 00, CC, CC, CC, CC, CC, CC, FF, 25, 38, 10, 40, 00, CC, CC...
 
[+]

Entropy:
6.0127

Code size:
48.5 KB (49,664 bytes)

Remove Microsoft.DirectX.AudioVideoPlayback.dll - Powered by Reason Core Security