uilogic.dll

ChengDu AoMei Tech Co., Ltd

The library uilogic.dll has been detected as malware by 3 anti-virus scanners.
Publisher:
ChengDu AoMei Tech Co., Ltd  (signed and verified)

MD5:
334257ebe8376c5fda57eac334e6e795

SHA-1:
44484116f8dc662bcde096a9e7d2d1fe576f95ec

SHA-256:
1f7a44cf75208201b9f5a4b744ff3815e4ff8b39f3926751d9b5c5077e354375

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
4/19/2024 4:28:20 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.16.24

File size:
268.2 KB (274,591 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\aomei backupper\uilogic.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/25/2013 5:00:00 PM

Valid to:
6/25/2016 4:59:59 PM

Subject:
CN="ChengDu AoMei Tech Co., Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="ChengDu AoMei Tech Co., Ltd", L=Chengdu, S=Sichuan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3B6BF2A79BBEFAEEFF04087FFE96CF15

File PE Metadata
Compilation timestamp:
8/23/2013 5:01:20 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

Entry address:
0x2183A

Entry point:
E9, FD, FE, FE, FF, 75, 05, E8, DA, 04, 00, 00, FF, 74, 24, 04, 8B, 4C, 24, 10, 8B, 54, 24, 0C, E8, CD, FE, FF, FF, 59, C2, 0C, 00, 6A, 14, 68, 40, 6D, 02, 10, E8, 3D, 04, 00, 00, FF, 35, BC, AA, 02, 10, 8B, 35, E8, 41, 02, 10, FF, D6, 59, 89, 45, E4, 83, F8, FF, 75, 0C, FF, 75, 08, FF, 15, 0C, 42, 02, 10, 59, EB, 67, 6A, 08, E8, 2F, 05, 00, 00, 59, 83, 65, FC, 00, FF, 35, BC, AA, 02, 10, FF, D6, 89, 45, E4, FF, 35, B8, AA, 02, 10, FF, D6, 59, 59, 89, 45, E0, 8D, 45, E0, 50, 8D, 45, E4, 50, FF, 75, 08, 8B...
 
[+]

Entropy:
6.9553

Packer / compiler:
Xtreme-Protector v1.05

Code size:
140 KB (143,360 bytes)

Remove uilogic.dll - Powered by Reason Core Security