shellextension.dll

TTNET A.S.

It is registered as a context menu handler (displays a menu when right-clicked in Explorer) named “MemopalShell”.
Publisher:
TTNET A.S.  (signed and verified)

MD5:
2f2274523d5d60bc9059d3906e66b3eb

SHA-1:
027e04dee01a80b715adffc5d43e885876d28c02

SHA-256:
8a0d569263048dd8f69defed7bb67ea193956b57be19556039b595e5f6858781

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 5:23:52 PM UTC  (today)

File size:
1.8 MB (1,885,832 bytes)

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\Program Files\netdisk\shellextensionx64\shellextension.dll

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/2/2013 6:26:11 PM

Valid to:
10/5/2016 11:15:44 AM

Subject:
CN=TTNET A.S., O=TTNET A.S., L=Sisli, S=Istanbul, C=TR

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112177DC54FE0F7FDEC07CD9BD779C27745C

Registration
CLSIDs:
{2CDD871E-60EB-40BD-9721-A1CB57042F75}, {723F4F64-AB80-46AF-9FF3-09D8C46C0746}, {8ED3CC2D-6BC2-43AD-8C43-F51FBB413AE6}, {95DDC869-FC98-4D47-BD34-2EDC9AA09C01}, {B9CA6E12-7975-4997-B5BD-CA12ECE0FEAD}

COM registered:
Yes

File PE Metadata
Compilation timestamp:
7/7/2014 12:38:46 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:r8nkTjT6t3mie4YjuM41QRL+fQxOD1WRkYJy1+2WW823jm:ffmN5ePS3wL+fQxOD1WRny1+2yt

Entry address:
0xD5448

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, E3, 02, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, 8B, FE, FF, FF, CC, CC, CC, 48, 89, 4C, 24, 08, 48, 81, EC, 88, 00, 00, 00, 48, 8D, 0D, B5, F5, 0C, 00, FF, 15, E7, 0D, 03, 00, 4C, 8B, 1D, A0, F6, 0C, 00, 4C, 89, 5C, 24, 58, 45, 33, C0, 48, 8D, 54, 24, 60, 48, 8B, 4C, 24, 58, E8, 45, 67, 00, 00, 48, 89, 44, 24, 50, 48, 83, 7C, 24...
 
[+]

Code size:
1 MB (1,068,032 bytes)

Context Menu Handler
Display name:
MemopalShell

CLSID:
{723F4F64-AB80-46AF-9FF3-09D8C46C0746}

CLSID name:
MemopalShellExtension


Scan shellextension.dll - Powered by Reason Core Security