y7shim.dll

yessign7 Shim DLL Module

yessign

Publisher:
금융결제원  (signed by yessign)

Product:
yessign7 Shim DLL Module

Version:
1, 0, 1, 14

MD5:
925a248800b2001fbb86b7165fb46fc3

SHA-1:
14040f59fe19fde2f9e39288fedac835d8d31561

SHA-256:
7294b6834d42f9827da9cb05ba225b46dc2f576f5610f45edc56cde4b9022ded

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
8/19/2018 7:59:24 PM UTC  (today)

Scan engine
Detection
Engine version

Trend Micro House Call
TROJ_GEN.F47V1003
7.2.355

File size:
37.7 KB (38,568 bytes)

Product version:
1, 0, 1, 14

Copyright:
Copyright (C) 2010

Original file name:
y7shim.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\windows\syswow64\y7shim.dll

Digital Signature
Signed by:

Authority:
yessign

Valid from:
8/13/2012 12:00:00 AM

Valid to:
9/6/2014 11:58:59 PM

Subject:
CN=금융결제원(KFTC), OU=02201009060001, OU=code-sign, O=yessign, C=kr

Issuer:
CN=yessignCA General Class 2, OU=AccreditedCA, O=yessign, C=kr

Serial number:
068A94510546D7BABC1C

File PE Metadata
Compilation timestamp:
7/2/2013 2:47:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
384:IOGnWWa2RE+/JKL07pXCd9e9xwxNFen2S1G/EpZMse0z:gWzKYL0lBxMren2J/hQz

Entry address:
0x29CB

Entry point:
55, 8B, EC, 53, 8B, 5D, 08, 56, 8B, 75, 0C, 57, 8B, 7D, 10, 85, F6, 75, 09, 83, 3D, A0, 49, 00, 10, 00, EB, 26, 83, FE, 01, 74, 05, 83, FE, 02, 75, 22, A1, C4, 49, 00, 10, 85, C0, 74, 09, 57, 56, 53, FF, D0, 85, C0, 74, 0C, 57, 56, 53, E8, 15, FF, FF, FF, 85, C0, 75, 04, 33, C0, EB, 4E, 57, 56, 53, E8, E5, E5, FF, FF, 83, FE, 01, 89, 45, 0C, 75, 0C, 85, C0, 75, 37, 57, 50, 53, E8, F1, FE, FF, FF, 85, F6, 74, 05, 83, FE, 03, 75, 26, 57, 56, 53, E8, E0, FE, FF, FF, 85, C0, 75, 03, 21, 45, 0C, 83, 7D, 0C, 00...
 
[+]

Entropy:
4.1400

Developed / compiled with:
Microsoft Visual C++ 6.0

Code size:
8 KB (8,192 bytes)

ActiveX Install
Name:
{B0A75875-3622-48BA-B5FF-45AD77AC2D0E}


Scan y7shim.dll - Powered by Reason Core Security