multishop.dll

MultiShop

Media Labs Limited

The module multishop.dll, “находит и подсвечивает товары на странице” by Media Labs Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘MultiShop v2.1’.
Publisher:
Media Labs Limited  (signed and verified)

Product:
MultiShop

Description:
находит и подсвечивает товары на странице

Version:
2.1.1.20

MD5:
de5c878b160daef7ccfa7a17d9beb5c7

SHA-1:
0235876f9767ea6093c41f9933b5dfe7e13d9999

SHA-256:
8eb66feb55111ffc034e7e59b69d6a2bdd88d6f03792cbcb15e137de238a44a6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/27/2024 2:43:03 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Media Labs.MediaLabs (M)
16.2.10.6

File size:
868.1 KB (888,920 bytes)

Product version:
2.0

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\ticno\multibar\multishop.dll

Digital Signature
Authority:
The USERTRUST Network

Valid from:
6/3/2010 3:00:00 AM

Valid to:
6/4/2011 2:59:59 AM

Subject:
CN=Media Labs Limited, O=Media Labs Limited, STREET="Varshavskoe ave, 33", STREET=n/a, L=Moscow, S=Moscow, PostalCode=117105, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
008F690EC25799DD98DD8CFD42DCB88EE9

File PE Metadata
Compilation timestamp:
11/27/2010 12:51:37 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:o0FOIHRgpHUANdCFTjvwkpKH5bPGD+VRQZJx0yPob+v7FjA3/C9zE:PrR4ZPCF/vwkpKZSD+VRQZJxJobS

Entry address:
0x8A99C

Entry point:
55, 8B, EC, 83, C4, C4, B8, 6C, 99, 48, 00, E8, 60, C7, F7, FF, E8, D3, A1, F7, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
550 KB (563,200 bytes)

Internet Explorer BHO
CLSID:
{39AA6D29-4236-4F25-A36A-3410EF5283D9}

CLSID name:
MultiShop v2.1


Remove multishop.dll - Powered by Reason Core Security