TFBroker.DLL

TFBroker Module

Comsquare Corp

Publisher:
Comsquare  (signed by Comsquare Corp)

Product:
TFBroker Module

Version:
1, 0, 1, 0

MD5:
a594453205702727ce4b5672ef71df82

SHA-1:
27d4817b390eca98541cc4ba80b0fd4b13953600

SHA-256:
32ce945c0e7ee8bff795d29313d15ceacaef09100bef3ad070903bf64c097247

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 4:50:33 AM UTC  (today)

File size:
841.5 KB (861,672 bytes)

Product version:
1, 0, 0, 8

Copyright:
Copyright 2007

Original file name:
TFBroker.DLL

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Windows\System32\tfbroker.dll

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
10/20/2008 5:31:35 PM

Valid to:
10/31/2010 5:30:53 PM

Subject:
CN=Comsquare Corp, OU=Development Department, O=Comsquare Corp, L=SEOUL, S=GYEONGGI-DO, C=KR

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
67CC555F9B7ABC46DD0183D62A4F7ED4

Registration
CLSID:
{0DFA67D7-B78C-40A7-B583-E7090D5F38C6}

ProgID:
TFBroker.FileManager.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
8/5/2010 5:28:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:AjgCul5PJuRnIG+Kxlp+3YvZgx+hnYK9StT5stnyBKojrjX7FnOS:Akd5uRI3KxbXvZ9zSJynr0f

Entry address:
0x49B18

Entry point:
E9, 73, 79, 03, 00, E9, 2E, EE, 01, 00, E9, E9, FD, 00, 00, E9, 14, DB, 02, 00, E9, 07, C0, 02, 00, E9, 24, BF, 02, 00, E9, A5, 3A, 01, 00, E9, 60, DA, 03, 00, E9, 1B, 86, 01, 00, E9, D6, C1, 08, 00, E9, 81, 82, 02, 00, E9, 7C, 7E, 02, 00, E9, D7, 7D, 04, 00, E9, 82, B6, 01, 00, E9, BD, 52, 07, 00, E9, F8, 22, 03, 00, E9, 43, B2, 01, 00, E9, 8E, 47, 01, 00, E9, 49, DC, 03, 00, E9, D6, 44, 05, 00, E9, BF, 32, 02, 00, E9, FA, 3F, 05, 00, E9, 15, CD, 03, 00, E9, 40, 05, 03, 00, E9, CB, 80, 07, 00, E9, B6, 37...
 
[+]

Entropy:
5.6853

Developed / compiled with:
Microsoft Visual C++ 8.0 (Debug)

Code size:
612 KB (626,688 bytes)

ActiveX Install
Name:
{ED5D862B-6A06-46DE-A929-F2C588742CBD}


Scan TFBroker.DLL - Powered by Reason Core Security