xgvr.dll

西瓜影视

Suining Qixi Advertising Media Co., Ltd.

The module xgvr.dll by Suining Qixi Advertising Media Co. has been detected as a potentially unwanted program by 2 anti-malware scanners.
Publisher:

Product:
西瓜影视

Description:
VideoRenderers

Version:
1,0,0,2

MD5:
98fcaa3c28b67507970c9ced3450b591

SHA-1:
de726945e5bbfdc8ae97b79ef319f6e1171ee6de

SHA-256:
c4cfe4cd65a8402771eb1cec6ad5968d1a537f42d20c04bbb4bced278a2d87b4

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 7:01:19 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Suining
2016.0.3215

Reason Heuristics
PUP.SuiningQixiAdvertisingMediaCo
15.1.29.1

File size:
906.7 KB (928,424 bytes)

Product version:
1,0,0,2

Copyright:
Copyright (C) 2014

Original file name:
VideoRenderers.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Chinese (Simplified, China)

Common path:
C:\Program Files\xigua\2.12.0.5\xgvr.dll

Digital Signature
Authority:
WoSign CA Limited

Valid from:
4/21/2014 5:14:06 AM

Valid to:
4/23/2017 5:14:06 AM

Subject:
CN="Suining Qixi Advertising Media Co., Ltd.", E=xiguayingyin@gmail.com, O="Suining Qixi Advertising Media Co., Ltd.", L=Suining, S=Jiangsu, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
6BA70B4380ECA6E171FB81A495EC5DEF

File PE Metadata
Compilation timestamp:
7/2/2014 6:57:43 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:7kUpRXNErmDXSoE8N58w6pGbSiQqZrOqu:dpRX24XSoE8N5gMSQZrq

Entry address:
0x7761E

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, BF, 8F, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63, FC, FF, E0, 5B, C9, C2, 08, 00, 58, 59, 87, 04, 24, FF, E0, 8B, FF, 55, 8B, EC, 51, 51, 53, 56, 57, 64, 8B, 35, 00, 00, 00, 00, 89, 75, FC, C7, 45, F8, A5, 76, 07, 10, 6A, 00, FF, 75, 0C, FF, 75, F8, FF...
 
[+]

Entropy:
6.4800

Code size:
589 KB (603,136 bytes)

Remove xgvr.dll - Powered by Reason Core Security