eshellctx.dll

WinZipper

EMG Technology Limited

The module eshellctx.dll, “WinZipper Shell Context Menu” by EMG Technology Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program AirZip by EMG Technology Limited which is a potentially unwanted software program.
Publisher:
337 Technology Limited.  (signed by EMG Technology Limited)

Product:
WinZipper

Description:
WinZipper Shell Context Menu

Version:
0.0.0.1

MD5:
8bdc2137fbc5f89dbf6f00ddbafdfb41

SHA-1:
5478e02e9ef102c23b67fad37faa748337571749

SHA-256:
eb3066d20bb9b6b73196ceeea256247c9968707558a82d63bf300278794d8b0d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 8:00:14 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.2.9.15

File size:
72.1 KB (73,872 bytes)

Product version:
0.0.0.1

Copyright:
Copyright (C) 2012

Original file name:
eshellctx.exe

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\airzip\eshellctx.dll

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/31/2013 1:20:50 AM

Valid to:
8/1/2014 1:20:50 AM

Subject:
CN=EMG Technology Limited, O=EMG Technology Limited, L=HongKong, S=HongKong, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11214B00008DA514B60ED8EE5329E4DF7F28

Registration
CLSID:
{4F622628-7632-4B28-B184-D7BA0CA3273B}

COM registered:
Yes

File PE Metadata
Compilation timestamp:
10/14/2013 7:56:25 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:haeB7RMaenytff3sSX/lUvAcYu1b8eWlcObvW8E2cuY9s:haHytff3sYEA85WeObvW8E23Y9s

Entry address:
0x9B3A

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 7A, 03, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, CC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, FF, 25, 8C, B1, 00, 10, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 68, C9, 9B, 00, 10, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 30, F9, 00, 10, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89...
 
[+]

Entropy:
6.3561

Code size:
40 KB (40,960 bytes)

Approved Shell Extension
Name:
WinZipper Shell Extension

CLSID:
{4F622628-7632-4B28-B184-D7BA0CA3273B}

CLSID name:
OShellContextMenu Class


The file eshellctx.dll has been discovered within the following program.

AirZip  by EMG Technology Limited
Publisher's description - “Airzip is a free and easy to use compression software that is based on 7-Zip technology. With its fast compression engine,Airzip is a powerful tool for unzipping Zip archives, creating Zip-compatible files and other archiving software.”
airzip.webssearches.com
About 60% of users remove it
 
Powered by Should I Remove It?

Remove eshellctx.dll - Powered by Reason Core Security