Desktop.DLL

Desktop Dynamic Link Library

重庆话语科技有限公司

Publisher:
重庆话语科技有限公司  (signed and verified)

Product:
Desktop Dynamic Link Library

Description:
Desktop DLL

Version:
1, 0, 0, 1

MD5:
8dd5ae50ccf238e42e035eb7b587380e

SHA-1:
988ca728f5770838ac20d4e72899db3b44e48110

SHA-256:
45d19e7d54bf059220a94013c8a138d49168159e6317a2f770a04868c66df599

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/26/2024 9:40:50 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.Cloddff.Trojan
1.3.0.4959

File size:
147 KB (150,552 bytes)

Product version:
1, 0, 0, 1

Copyright:
版权所有 (C) 2011

Original file name:
Desktop.DLL

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\kooping\desktop.dll

Digital Signature
Authority:
Thawte, Inc.

Valid from:
6/27/2011 8:00:00 AM

Valid to:
6/27/2012 7:59:59 AM

Subject:
CN=重庆话语科技有限公司, O=重庆话语科技有限公司, L=Chongqing, S=Chongqing, C=CN

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
41908564ADF2B8576F870159DA77C2AB

File PE Metadata
Compilation timestamp:
8/9/2011 3:56:11 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:R4r/0V6Jy3RzNC4i9oo/6padU1HTnhmItrzBfHoqnbpt:quzw9u8ItnBQmpt

Entry address:
0xCE05

Entry point:
55, 8B, EC, 53, 8B, 5D, 08, 56, 8B, 75, 0C, 57, 8B, 7D, 10, 85, F6, 75, 09, 83, 3D, 54, F1, 01, 10, 00, EB, 26, 83, FE, 01, 74, 05, 83, FE, 02, 75, 22, A1, 40, C1, 01, 10, 85, C0, 74, 09, 57, 56, 53, FF, D0, 85, C0, 74, 0C, 57, 56, 53, E8, 15, FF, FF, FF, 85, C0, 75, 04, 33, C0, EB, 4E, 57, 56, 53, E8, 6B, 7F, FF, FF, 83, FE, 01, 89, 45, 0C, 75, 0C, 85, C0, 75, 37, 57, 50, 53, E8, F1, FE, FF, FF, 85, F6, 74, 05, 83, FE, 03, 75, 26, 57, 56, 53, E8, E0, FE, FF, FF, 85, C0, 75, 03, 21, 45, 0C, 83, 7D, 0C, 00...
 
[+]

Entropy:
6.2151

Developed / compiled with:
Microsoft Visual C++ 6.0

Code size:
92 KB (94,208 bytes)

Scan Desktop.DLL - Powered by Reason Core Security