WRusr.dll

Webroot SecureAnywhere

Webroot Inc.

It is registered as a context menu handler (displays a menu when right-clicked in Explorer) named “WRShellExt”.
Scan WRusr.dll - Powered by Reason Core Security
Publisher:
Webroot  (signed by Webroot Inc.)

Product:
Webroot SecureAnywhere

Version:
8.0.4.73

MD5:
4dd3de3f5a5ba7211019682dc568d362

SHA-1:
0520b3df223ed6fc0e6cd0f10c5dbc41aaaa2d6e

SHA-256:
e6e359aeff096e63cdef15164e7740f6941e6c6c7098d89f5a100896984f7947

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/4/2016 7:17:49 AM UTC  (today)

File size:
151.1 KB (154,760 bytes)

Product version:
8.0.4.73

Copyright:
(c) Webroot 2006-2014

Original file name:
WRusr.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Windows\System32\wrusr.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/23/2013 5:30:00 AM

Valid to:
2/22/2016 5:29:59 AM

Subject:
CN=Webroot Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Webroot Inc., L=Broomfield, S=Colorado, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0F93940D35AB8B900B117F5574BA1090

Registration
CLSIDs:
{1914B27A-33C8-46F8-A1C2-F993268D4564}, {69D72956-317C-44bd-B369-8E44D4EF9802}, {6DA1ED92-315E-4D0B-B354-9D5F519DBA95}, {8D7FC74C-E409-42DF-8EEE-69D45FAE2F30}, {C14874EA-ACE4-4A47-8A81-18C4D1C40868}

COM registered:
Yes

File PE Metadata
Compilation timestamp:
6/6/2014 3:41:47 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
3072:C37TBfRNvrzMsUMmi7eQ6tICYOx3fdTp3/o49jgsSZmhCr7eGWkvlJRNqFCso/D:C37TB/rz9UMmi7eQ6tnl3/o490s7ie7c

Entry address:
0x1C360

Entry point:
8B, FF, 55, 8B, EC, 8B, 45, 0C, 83, E8, 00, 74, 29, 83, E8, 01, 75, 29, 56, 8B, 75, 08, 56, FF, 15, C8, 10, 00, 10, 33, C0, 39, 45, 10, 0F, 94, C0, 50, 56, E8, 64, FF, FF, FF, 5E, B8, 01, 00, 00, 00, 5D, C2, 0C, 00, E8, F5, FC, FF, FF, B8, 01, 00, 00, 00, 5D, C2, 0C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 8B, 4D, 0C, 8B, 55, 08, B8, 10, 00, 00, 00, 56, 8B, 32, 3B, 31, 75, 1E, 83, E8, 04, 83, C1, 04, 83, C2, 04, 83, F8, 04, 73, EC, 33, C0, 33, D2, 85, C0, 0F, 94, C2, 5E, 8B...
 
[+]

Entropy:
6.6847

Code size:
121 KB (123,904 bytes)

Context Menu Handler
Display name:
WRShellExt

CLSID:
{69D72956-317C-44bd-B369-8E44D4EF9802}

CLSID name:
WRShellExt


Scan WRusr.dll - Powered by Reason Core Security