PNCRT.DLL

RealPlayer/RealServer

Suining Qixi Advertising Media Co., Ltd.

The module PNCRT.DLL, “Real Networks C/C++ Runtime Library” by Suining Qixi Advertising Media Co. has been detected as a potentially unwanted program by 2 anti-malware scanners.
Publisher:
Real Networks, Inc  (signed by Suining Qixi Advertising Media Co., Ltd.)

Product:
RealPlayer/RealServer

Description:
Real Networks C/C++ Runtime Library

Version:
6.0.0.0

MD5:
5895cbce3ed698f9884460118598d9a7

SHA-1:
550f9a0099fc28ffec09def905825adb1e207d02

SHA-256:
95b5003475dc1f7bd9c3ea8d979ed5bde58bf052e15e8129d603f443d6e5f84d

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 9:53:48 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Suining
2016.0.3215

Reason Heuristics
PUP.SuiningQixiAdvertisingMediaCo
15.1.29.1

File size:
279.7 KB (286,376 bytes)

Product version:
6.0.0.0

Copyright:
Copyright (C) Real Networks 1999

Original file name:
PNCRT.DLL

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\xigua\2.12.0.5\pncrt.dll

Digital Signature
Authority:
WoSign CA Limited

Valid from:
4/21/2014 5:14:06 AM

Valid to:
4/23/2017 5:14:06 AM

Subject:
CN="Suining Qixi Advertising Media Co., Ltd.", E=xiguayingyin@gmail.com, O="Suining Qixi Advertising Media Co., Ltd.", L=Suining, S=Jiangsu, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
6BA70B4380ECA6E171FB81A495EC5DEF

File PE Metadata
Compilation timestamp:
6/22/2001 6:44:03 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.10

CTPH (ssdeep):
6144:Xm7wHLiH0k6OgfjvQ0mvlxZ/PeT8Ah8EoHiIKaGo5RpTufufVvtr+dj7GcuT1JO3:Xm7KLiHl6OgfjvQ0m93/5q+iIKaGo5RC

Entry address:
0x9010

Entry point:
8B, 44, 24, 08, 53, 83, F8, 01, 56, 0F, 85, CA, 00, 00, 00, FF, 15, 38, 60, A5, 60, 8B, D8, 8B, F3, 81, E6, FF, 00, 00, 00, 83, FE, 03, 75, 26, F7, C3, 00, 00, 00, 80, 74, 1E, 68, 10, 20, 01, 00, 68, 38, 6D, A5, 60, 68, 98, 6D, A5, 60, E8, 70, 3D, 00, 00, 83, C4, 0C, 33, C0, 5E, 5B, C2, 0C, 00, E8, 61, 1E, 00, 00, 85, C0, 75, 05, 5E, 5B, C2, 0C, 00, 8B, C6, 33, C9, A3, E4, 1D, A6, 60, 8A, CF, C1, E0, 08, 03, C1, 89, 0D, E8, 1D, A6, 60, C1, EB, 10, A3, E0, 1D, A6, 60, 89, 1D, DC, 1D, A6, 60, E8, 7F, 0B, 00...
 
[+]

Entropy:
6.6814

Code size:
212 KB (217,088 bytes)

Remove PNCRT.DLL - Powered by Reason Core Security