ws2help.dll

Windows Socket 2.0 Helper for Windows NT

Microsoft Corporation

The library ws2help.dll, “Windows Socket 2.0 Helper for Windows NT” has been detected as malware by 34 anti-virus scanners.
Publisher:
Microsoft Corporation

Product:
Microsoft® Windows® Operating System

Description:
Windows Socket 2.0 Helper for Windows NT

Version:
5.1.2600.5512 (xpsp.080413-0852)

MD5:
bd3abf75a8f740e3cda02f8acddaccf8

SHA-1:
36095cb1586443838b46013721ca206c5f61054b

Scanner detections:
34 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/27/2024 1:23:47 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Win32.Slugin.A
7.1.1

AhnLab V3 Security
Win32/Slugin
2013.10.25

Avira AntiVirus
W32/Slugin.A
7.11.109.96

avast!
Win32:Patched-HO [Trj]
2014.9-140729

AVG
Win32/Slugin.A
2015.0.3398

Baidu Antivirus
Virus.Win32.Patched.$dj
4.0.3.14910

Bitdefender
Win32.SlugIn.A
1.0.20.1050

Bkav FE
W32.OlayFara.PE
1.3.0.4261

Comodo Security
TrojWare.Win32.Patched.P
17154

Dr.Web
Win32.Wplugin.1
9.0.1.0210

Emsisoft Anti-Malware
Win32.SlugIn
8.14.07.29.08

ESET NOD32
Win32/Slugin
8.8963

Fortinet FortiGate
W32/Wplug.A
7/29/2014

F-Prot
W32/Slugin.B
v6.4.7.1.166

G Data
Win32.SlugIn
14.7.22

IKARUS anti.virus
Trojan.Win32.Patched
t3scan.2.0.127

K7 AntiVirus
Trojan
13.173.9980

Kaspersky
Trojan.Win32.Patched
14.0.0.3486

McAfee
W32/Wplugin.dll
5600.7054

Microsoft Security Essentials
Virus:Win32/Slugin.A!dll
1.163.1557.3

MicroWorld eScan
Win32.SlugIn.A
15.0.0.759

NANO AntiVirus
Trojan.Win32.Patched.boyum
0.26.0.55532

Norman
Agent.VDAZ
11.20140729

nProtect
Win32.SlugIn.A
13.10.25.02

Panda Antivirus
W32/Wplugin.A
14.07.29.08

Quick Heal
W32.Slugin.A
7.14.12.00

Rising Antivirus
Win32.Agent.ik
23.00.65.14908

Sophos
W32/Slugin-A
4.94

Total Defense
Win32/Slugin.A
37.0.10498

Trend Micro House Call
PE_WPLUG.A-1
7.2.210

Trend Micro
PE_WPLUG.A-1
10.465.29

Vba32 AntiVirus
Trojan.Patched.dj
3.12.24.3

VIPRE Antivirus
Virus.Win32.Slugin.a
22702

ViRobot
Win32.Patched.N
2011.4.7.4223

File size:
20.7 KB (21,172 bytes)

Product version:
5.1.2600.5512

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
ws2help.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\yahoo!\messenger\ws2help.dll

File PE Metadata
Compilation timestamp:
4/14/2008 7:12:20 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
7.10

CTPH (ssdeep):
384:Z7h1n6Cufg7e0GZzwsUOWOJQz8zwL0lJXKBHlriWqmW3d+xEb:ZF16Dy4cjOW1z8ELHHlKPdhb

Entry address:
0x1638

Entry point:
60, E8, 00, 00, 00, 00, 5B, 81, EB, D0, 48, 00, 10, 83, EC, 74, 8B, EC, 8B, 83, AB, 4B, 00, 10, 89, 45, 00, 8B, 83, B3, 4B, 00, 10, 03, 45, 00, 89, 45, 2C, 8B, 83, B7, 4B, 00, 10, 03, 45, 00, 89, 45, 30, C7, 45, 14, 00, 00, 00, 00, C7, 45, 18, 00, 00, 00, 00, C7, 45, 1C, 00, 00, 00, 00, 8B, 45, 14, FF, 45, 14, 66, 33, C9, 8A, 8C, 03, FF, 4B, 00, 10, 84, C9, 74, 7A, 8B, 45, 1C, 66, 01, 4D, 1C, 03, C3, 05, 13, 4C, 00, 10, 50, 8B, 45, 2C, FF, 10, 85, C0, 0F, 84, 5E, 02, 00, 00, 89, 45, 10, 8B, 45, 1C, 03, C3...
 
[+]

Entropy:
6.1276

Packer / compiler:
ASPack v1.08.04

Code size:
15.5 KB (15,872 bytes)

Remove ws2help.dll - Powered by Reason Core Security