shellextension.dll

HGST, Inc.

It is registered as a context menu handler (displays a menu when right-clicked in Explorer) named “MemopalShell”.
Publisher:
HGST, Inc.  (signed and verified)

MD5:
3f802c98604c97429b65fbf8fc25baec

SHA-1:
63068b2b4ef6128887d92d1817198ae374877166

SHA-256:
33f750c8fe4e47b53007a57b85b3838c6bab17d7bdbee25cde7063ed7a045534

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/21/2026 12:58:47 AM UTC  (today)

File size:
2.1 MB (2,218,592 bytes)

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\Program Files\touro cloud backup\shellextensionx64\shellextension.dll

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
10/1/2014 9:01:36 AM

Valid to:
10/1/2015 9:01:36 AM

Subject:
CN="HGST, Inc.", O="HGST, Inc.", L=San Jose, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0462CBAB94FA06

Registration
CLSIDs:
{2CDD871E-60EB-40BD-9721-A1CB57042F75}, {723F4F64-AB80-46AF-9FF3-09D8C46C0746}, {8ED3CC2D-6BC2-43AD-8C43-F51FBB413AE6}, {95DDC869-FC98-4D47-BD34-2EDC9AA09C01}, {B9CA6E12-7975-4997-B5BD-CA12ECE0FEAD}

COM registered:
Yes

File PE Metadata
Compilation timestamp:
10/13/2014 12:42:33 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:plHgcrEB5lxtmGM6IgmmTND6ZP4VMcQxOD1WRiUmCVuUeSG8nBBsXfh6:bPrabvMptmIvcQxOD1WRitCVuUeuHcg

Entry address:
0xD7348

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, E3, 02, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, 8B, FE, FF, FF, CC, CC, CC, 48, 89, 4C, 24, 08, 48, 81, EC, 88, 00, 00, 00, 48, 8D, 0D, F5, 1B, 0D, 00, FF, 15, E7, 1E, 03, 00, 4C, 8B, 1D, E0, 1C, 0D, 00, 4C, 89, 5C, 24, 58, 45, 33, C0, 48, 8D, 54, 24, 60, 48, 8B, 4C, 24, 58, E8, 45, 67, 00, 00, 48, 89, 44, 24, 50, 48, 83, 7C, 24...
 
[+]

Entropy:
5.6767

Code size:
1 MB (1,078,784 bytes)

Context Menu Handler
Display name:
MemopalShell

CLSID:
{723F4F64-AB80-46AF-9FF3-09D8C46C0746}

CLSID name:
MemopalShellExtension


Scan shellextension.dll - Powered by Reason Core Security