XmlLite.dll

Microsoft XML Core Services

Utililab GmbH

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The module XmlLite.dll, “Microsoft XmlLite Library” by Utililab GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Utililab GmbH)

Product:
Microsoft XML Core Services

Description:
Microsoft XmlLite Library

Version:
1.1.1002.0

MD5:
c8f9d8d17f31d4b1b430a8e8e3de2802

SHA-1:
51665a22305f35435d7eada912019bb71cc774be

SHA-256:
99aeefcf21d63636737fb881fdb1280efb3bf343d44652c1f421c40a3ff37990

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 11:30:39 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Utililab.SystemOptimizer.Optional.Meta (L)
16.2.5.16

File size:
128.6 KB (131,728 bytes)

Product version:
1.1.1002.0

Copyright:
Copyright (C) Microsoft Corporation. 2005

Original file name:
XmlLite.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\utililab\driverupdater\xmllite.dll

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
1/30/2011 4:00:00 PM

Valid to:
1/30/2014 3:59:59 PM

Subject:
CN=Utililab GmbH, O=Utililab GmbH, STREET=Schumannstraße 17, L=Berlin, S=Berlin, PostalCode=10117, C=DE

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00B233BC32FCEFAC7A7B4F96557686C278

File PE Metadata
Compilation timestamp:
11/2/2006 2:44:37 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:FHekJbbLs0atItGxWuLEOFthW/dfmwcFKm:h/B3s0aatr7OvhWdmAm

Entry address:
0x116D

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 0F, 84, 4B, 4D, 00, 00, 5D, 90, 90, 90, 90, 90, 6A, 2C, 68, 38, 12, 44, 24, E8, 1A, FF, FF, FF, 8B, 4D, 0C, 33, D2, 42, 89, 55, E4, 33, F6, 89, 75, FC, 89, 0D, 00, C8, 45, 24, 3B, CE, 0F, 84, A7, 02, 00, 00, 3B, CA, 74, 05, 83, F9, 02, 75, 35, A1, F8, E7, 45, 24, 3B, C6, 0F, 85, 2F, F0, 00, 00, 39, 75, E4, 74, 59, C7, 45, FC, 02, 00, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 50, FF, FF, FF, 89, 45, E4, 89, 75, FC, 39, 75, E4, 74, 39, 8B, 4D, 0C, C7, 45, FC, 03, 00...
 
[+]

Entropy:
6.5023

Code size:
107 KB (109,568 bytes)

Remove XmlLite.dll - Powered by Reason Core Security