DBGHELP.DLL

Debugging Tools for Windows

Hefei Hejunzhengce Info Tech Co., Ltd.

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The library DBGHELP.DLL, “Windows Image Helper” has been detected as malware by 1 anti-virus scanner.
Publisher:
Microsoft Corporation  (signed by Hefei Hejunzhengce Info Tech Co., Ltd.)

Product:
Debugging Tools for Windows(R)

Description:
Windows Image Helper

Version:
6.12.0002.633 (debuggers(dbg).100201-1203)

MD5:
0255845c1490c12663a785d6ba4accbc

SHA-1:
44b5f5533d0da6210a9603ea7c799c14ec0a9035

SHA-256:
39c759296ee5adc9a7233c8228a061de7c876c81ba7888769d59d7dee86f89fb

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/16/2024 7:58:23 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.9.26.21

File size:
1.2 MB (1,212,400 bytes)

Product version:
6.12.0002.633

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
DBGHELP.DLL

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\google\chrome\application\46.10.2479.19\dbghelp.dll

Digital Signature
Authority:
WoSign CA Limited

Valid from:
3/6/2015 3:35:27 PM

Valid to:
12/30/2016 3:35:27 PM

Subject:
CN="Hefei Hejunzhengce Info Tech Co., Ltd.", O="Hefei Hejunzhengce Info Tech Co., Ltd.", L=Hefei, S=Anhui, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
3312D0B8D4D7941DF85AA59F134E7719

File PE Metadata
Compilation timestamp:
2/2/2010 4:08:26 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
24576:DAkmijauMug/iyFzb2DfsPV8A4C2vNI1cPdf8xZLGNfav9c:DWiOuRg/iyFzb2QN83XfeYaq

Entry address:
0x6C811

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 71, 15, 00, 00, 5D, E9, 89, FD, FF, FF, CC, CC, CC, CC, CC, 3B, 0D, 78, 69, 11, 03, 75, 03, C2, 00, 00, E9, EC, 15, 00, 00, CC, CC, CC, CC, CC, CC, FF, 25, 54, 11, 00, 03, CC, CC, CC, CC, CC, CC, FF, 25, 30, 12, 00, 03, CC, CC, CC, CC, CC, CC, FF, 25, 2C, 12, 00, 03, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 80, F9, 40, 73, 15, 80, F9, 20, 73, 06, 0F, A5, C2, D3, E0, C3, 8B, D0, 33, C0, 80, E1, 1F, D3, E2, C3, 33, C0, 33, D2, C3, CC, CC...
 
[+]

Entropy:
6.3836

Code size:
1.1 MB (1,124,352 bytes)

Remove DBGHELP.DLL - Powered by Reason Core Security