qhiknoni.dll

浏览器安全模块

Changsha Spring Culture Communications Ltd.

The library qhiknoni.dll, “浏览器安全模块(2014.01.08)” has been detected as malware by 8 anti-virus scanners.
Publisher:
HNSPRING  (signed by Changsha Spring Culture Communications Ltd.)

Product:
浏览器安全模块

Description:
浏览器安全模块(2014.01.08)

Version:
1.0

MD5:
0163c88e00257ddd6b6c39864f1688ab

SHA-1:
7673c47d43354d6d9ac5be7dcdf9f549453201bf

SHA-256:
70dabe03ecc120136ee2304fd9f7fd47e51c90a226f7f88024e9d64a41a40eec

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
4/20/2024 12:25:46 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.VMProtect
7.1.1

ESET NOD32
Win32/Packed.VMProtect.AAN (variant)
10.9578

Fortinet FortiGate
W32/FakeAV.OP!tr
1/7/2016

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.852

NANO AntiVirus
Trojan.Win32.FakeAVOP.ctcwsl
0.28.0.58491

Quick Heal
(Suspicious) - DNAScan
1.16.12.00

Sophos
Mal/FakeAV-OP
4.98

VIPRE Antivirus
Trojan.Win32.Generic
27668

File size:
1.8 MB (1,867,656 bytes)

Product version:
1.0

Copyright:
版权所有 (C) 1996-2012年 浏览器安全模块

Original file name:
IESAFE.DLL

File type:
Dynamic link library (Win32 DLL)

Language:
Chinese (Simplified, PRC)

Common path:
C:\windows\qhiknoni.dll

Digital Signature
Authority:
VeriSign, Inc.

Subject:
CN=Changsha Spring Culture Communications Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Changsha Spring Culture Communications Ltd., L=Changsha, S=Hunan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
55ECCB2274BCF4877B864F67ED1D1B49

File PE Metadata
Compilation timestamp:
1/8/2014 5:40:53 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:egWAzbXfiwTNXWAm7FwX02CUzfQw5x2V4jd2tadGQJU4yPc/gBtcrLAYd0:JEwTNXWADfz5QVW2lBKLAf

Entry address:
0x20B2B

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, B1, 2D, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, B0, FE, 03, 10, 89, 0D, AC, FE, 03, 10, 89, 15, A8, FE, 03, 10, 89, 1D, A4, FE, 03, 10, 89, 35, A0, FE, 03, 10, 89, 3D, 9C, FE, 03, 10, 66, 8C, 15, C8, FE, 03, 10, 66, 8C, 0D, BC, FE, 03, 10, 66, 8C, 1D, 98, FE, 03, 10, 66, 8C, 05, 94, FE, 03, 10, 66, 8C, 25, 90, FE, 03, 10, 66, 8C, 2D, 8C, FE, 03, 10, 9C, 8F, 05, C0, FE...
 
[+]

Entropy:
6.7251

Code size:
198 KB (202,752 bytes)

Remove qhiknoni.dll - Powered by Reason Core Security