qqiehelper01.dll

QQMiniDL Plugin

Tencent Technology(Shenzhen) Company Limited

It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘QQMiniDLBHOHelper’.
Publisher:
Tencent Technology (Shenzhen) Company Limited  (signed by Tencent Technology(Shenzhen) Company Limited)

Product:
QQMiniDL Plugin

Description:
QQMiniDL Plugin DLL

Version:
1, 2, 43, 400

MD5:
6d8d69dc40ae08bb38372624d25acd0c

SHA-1:
b5ec586b517f2a60ac82e8eb4589cfdbe31c86a4

SHA-256:
22a82bf0a40da890bf4b2bc5269aec370735c3705c0a30eee25651810e45d3e1

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/25/2024 1:42:58 PM UTC  (today)

Scan engine
Detection
Engine version

Sophos
Mal/Gampass-A
4.98

Trend Micro House Call
TROJ_GEN.F47V0121
7.2.110

File size:
547.6 KB (560,696 bytes)

Product version:
1, 2, 43, 400

Copyright:
Copyright(C) 1998 - 2013 TENCENT All Rights Reserved

Original file name:
QQIEHelper.DLL

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\common files\tencent\qqminidl\43\browser\qqiehelper01.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/17/2013 8:00:00 AM

Valid to:
2/17/2016 7:59:59 AM

Subject:
CN=Tencent Technology(Shenzhen) Company Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Tencent Technology(Shenzhen) Company Limited, L=shenzhen, S=guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7170BD93CF3F189AE6452B514C49340E

Registration
CLSIDs:
{3D735B62-B056-413a-9F4D-CF972EF01E66}, {5EA8DE18-C9EE-4af3-A54F-218FF055F5C0}, {C9C7334B-5657-41e1-8F79-F6AACECA05F4}

ProgIDs:
QQMiniDL.RightClick.1, QQMiniDL.IE.QQDownload.1, QQMiniDL.IE.Helper.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
12/20/2013 4:38:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:g6RydYyNfYX4eGfCHBq/Ng2JsNu/XS2TFG:1yDCHBq/j6kPl

Entry address:
0x33C3C

Entry point:
83, 7C, 24, 08, 01, 75, 05, E8, AC, EC, 00, 00, FF, 74, 24, 04, 8B, 4C, 24, 10, 8B, 54, 24, 0C, E8, ED, FE, FF, FF, 59, C2, 0C, 00, 8B, 4C, 24, 04, EB, 07, 49, 80, 38, 00, 74, 06, 40, 85, C9, 75, F5, 49, 8B, 44, 24, 04, 2B, C1, 48, C3, 55, 8B, EC, 83, EC, 14, A1, 30, 5A, 07, 10, 33, C5, 89, 45, FC, 53, 56, 33, DB, 39, 1D, 24, 77, 07, 10, 57, 8B, F1, 75, 38, 53, 53, 33, FF, 47, 57, 68, 1C, 4D, 06, 10, 68, 00, 01, 00, 00, 53, FF, 15, 7C, D1, 05, 10, 85, C0, 74, 08, 89, 3D, 24, 77, 07, 10, EB, 15, FF, 15, 34...
 
[+]

Entropy:
6.5943

Code size:
368 KB (376,832 bytes)

Internet Explorer BHO
Display name:
QQMiniDLBHOHelper

CLSID:
{C9C7334B-5657-41e1-8F79-F6AACECA05F4}


Scan qqiehelper01.dll - Powered by Reason Core Security