qqdownload.zip.tdl

Hefei Infinity Technology Co., Ltd.

The file qqdownload.zip.tdl by Hefei Infinity Technology Co. has been detected as a potentially unwanted program by 2 anti-malware scanners.
Publisher:
TDataDld  (signed by Hefei Infinity Technology Co., Ltd.)

Product:
TDataDld

Version:
1.0.0.47

MD5:
0bf311fb115214d42d503f111f009f9a

SHA-1:
f4cc6165ecfba6dfb2d75f386a5b2446a6c01e42

SHA-256:
a2c29101e07bd33909d5dc979e254bd8df1c802170c36111201d2c7249ee8da1

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
5/17/2024 9:19:37 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/ELEX.IN potentially unwanted application
8.0.319.0

Reason Heuristics
PUP.ELEX.HefeiInf (M)
16.7.17.7

File size:
2.1 MB (2,228,453 bytes)

Copyright:
Copyroght (c) 2011-2016 TDataDld system

Common path:
C:\users\{user}\appdata\roaming\tencent\qqphonemanager\components\qqdownload.zip.tdl

Digital Signature
Authority:
thawte, Inc.

Valid from:
6/22/2016 12:00:00 AM

Valid to:
9/7/2017 11:59:59 PM

Subject:
CN="Hefei Infinity Technology Co., Ltd.", O="Hefei Infinity Technology Co., Ltd.", L=Hefei, S=Anhui, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
28D850F553C2B1BA519F637BD531616D

File PE Metadata
Compilation timestamp:
3/22/2010 2:59:20 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:2GPHQTWvVRnGpOUblUQuZDP++8T1AOasCjG/E2h:20yWDqJWzZmmOaFG/E2h

Entry address:
0x114A

Entry point:
E9, F1, 55, 00, 00, E9, 0C, 95, 00, 00, E9, 47, B9, 00, 00, E9, 52, 99, 00, 00, E9, AD, 94, 00, 00, E9, C8, A9, 00, 00, E9, 43, 9A, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC...
 
[+]

Packer / compiler:
Xtreme-Protector v1.05

Code size:
62 KB (63,488 bytes)

Remove qqdownload.zip.tdl - Powered by Reason Core Security