XmlLite.dll

Microsoft XML Core Services

Software Marketing Ltd

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The module XmlLite.dll, “Microsoft XmlLite Library” by Software Marketing has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Software Marketing Ltd)

Product:
Microsoft XML Core Services

Description:
Microsoft XmlLite Library

Version:
1.1.1002.0

MD5:
d07a5b51a343fefe63d23f97b2fe9aa4

SHA-1:
4dbff5466606ffd88a3ac4c9ba7784deab2bf1f2

SHA-256:
8a97cb094f95b39d8a71dc47ae4debff4e1c6ed5650b8550fc798976f12f0240

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 5:19:01 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SoftwareMarketing.Meta (L)
16.1.22.8

File size:
129.5 KB (132,608 bytes)

Product version:
1.1.1002.0

Copyright:
Copyright (C) Microsoft Corporation. 2005

Original file name:
XmlLite.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\ultra pc care\xmllite.dll

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
6/14/2011 2:59:41 AM

Valid to:
6/14/2013 2:59:41 AM

Subject:
CN=Software Marketing Ltd, O=Software Marketing Ltd, L=Hong Kong, S=HK, C=HK

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B74A3CB7B3F71

File PE Metadata
Compilation timestamp:
11/2/2006 10:44:37 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:BHekJbbLs0atItGxWuLEOFthW/dfmwcFKuR:l/B3s0aatr7OvhWdmAuR

Entry address:
0x116D

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 0F, 84, 4B, 4D, 00, 00, 5D, 90, 90, 90, 90, 90, 6A, 2C, 68, 38, 12, 44, 24, E8, 1A, FF, FF, FF, 8B, 4D, 0C, 33, D2, 42, 89, 55, E4, 33, F6, 89, 75, FC, 89, 0D, 00, C8, 45, 24, 3B, CE, 0F, 84, A7, 02, 00, 00, 3B, CA, 74, 05, 83, F9, 02, 75, 35, A1, F8, E7, 45, 24, 3B, C6, 0F, 85, 2F, F0, 00, 00, 39, 75, E4, 74, 59, C7, 45, FC, 02, 00, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 50, FF, FF, FF, 89, 45, E4, 89, 75, FC, 39, 75, E4, 74, 39, 8B, 4D, 0C, C7, 45, FC, 03, 00...
 
[+]

Code size:
107 KB (109,568 bytes)

Remove XmlLite.dll - Powered by Reason Core Security