d3dcompiler_47.dll

Direct3D HLSL Compiler for Redistribution

Yupeng Zhang

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The module d3dcompiler_47.dll, “Direct3D HLSL Compiler for Redistribution” by Yupeng Zhang has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Yupeng Zhang)

Product:
Microsoft® Windows® Operating System

Description:
Direct3D HLSL Compiler for Redistribution

Version:
6.3.9600.16384 (winblue_rtm.130821-1623)

MD5:
79726081035f4409d5882a6766ffaaf2

SHA-1:
bea3ddfe4914c6cf9cfe928e2f08aa98886fa5c9

SHA-256:
165bc8fdff0c445ca446ea548489bd7722fa96c3de3c63d771cb3f10be7d2189

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
1/13/2025 7:12:35 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Zhang.YupengZh.Meta (M)
16.7.1.16

File size:
3.3 MB (3,456,384 bytes)

Product version:
6.3.9600.16384

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
d3dcompiler_47.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\chroomium browser\chroomium\d3dcompiler_47.dll

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
10/23/2015 2:00:00 AM

Valid to:
10/23/2016 1:59:59 AM

Subject:
CN=Yupeng Zhang, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
182977886EA709BC13B5E49D243C3907

File PE Metadata
Compilation timestamp:
8/22/2013 5:50:06 AM

OS version:
6.3

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

CTPH (ssdeep):
49152:8yZ9lnpmVm/w+EwVOmufvkQS8MH2J9CqS5Sqr88pPWW5KhQYPsXqUiQC:N9fWAwVBC8MH2JNSF8+YPsXqUTC

Entry address:
0x30E737

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, D1, 08, 00, 00, 5D, E9, 2A, 00, 00, 00, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, B8, 63, 73, 6D, E0, 39, 45, 08, 75, 0D, FF, 75, 0C, 50, E8, 36, 07, 00, 00, 59, 59, 5D, C3, 33, C0, 5D, C3, CC, CC, CC, CC, CC, 6A, 2C, 68, B8, 8F, 31, 10, E8, 49, 09, 00, 00, C7, 45, E4, 01, 00, 00, 00, 33, F6, 89, 75, FC, 8B, 45, 0C, 83, F8, 01, 77, 05, A3, 00, A0, 31, 10, 83, 7D, 0C, 00, 75, 11, 83, 3D, 40, FC, 31, 10, 00, 75, 08, 89, 75, E4, E9, 1E, 02, 00, 00, 8B, 45, 0C, 83...
 
[+]

Code size:
3.1 MB (3,245,568 bytes)

Remove d3dcompiler_47.dll - Powered by Reason Core Security