gsrld.dll

The library gsrld.dll has been detected as malware by 7 anti-virus scanners. The file has been seen being downloaded from dc544.4shared.com and multiple other hosts.
MD5:
a40530fa4a1e4aaa40e3f3a46a35d25b

SHA-1:
8b5596b4c0b0ce1b20ea58a84839720ff251be17

SHA-256:
ddde01f8c5a6f5d6a9cfde4a84acc9100f5fb6c7702c73ca36caf1aee2b86c59

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
12/26/2024 2:14:17 PM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
UnclassifiedMalware
17650

McAfee
Artemis!A40530FA4A1E
5600.7241

Norman
Suspicious_Gen2.VJRFC
11.20140123

Panda Antivirus
Trj/Thed.W
14.01.23.05

Reason Heuristics
Unnamed.Threat.23
14.2.26.11

Rising Antivirus
PE:Trojan.Win32.Generic.13F38508!334726408
23.00.65.14121

VIPRE Antivirus
Trojan.Win32.Generic
25658

File size:
69.5 KB (71,168 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\rockstar games\max payne 3\gsrld.dll

File PE Metadata
Compilation timestamp:
11/16/2012 12:56:33 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:Z2IIohsqs9v+iWvnjxCHVnj1VP3cuko2GuO54:jqV+nl4pB3cEs

Entry address:
0x1B20

Entry point:
B8, 01, 00, 00, 00, C2, 0C, 00, CC, CC, CC, CC, CC, CC, CC, CC, E9, BA, 6C, 00, 00, F6, C6, 37, 66, 0F, BC, C4, F5, 66, 0F, C8, 8B, 45, 00, C0, FA, 05, 66, 0F, BA, E7, 05, C0, F2, 06, 18, EA, 8A, 55, 04, E8, E5, 00, 00, 00, E8, 23, F8, FF, FF, 9C, 83, ED, 04, C7, 04, 24, 48, DF, 1F, D6, 53, 89, 55, 00, 66, C7, 04, 24, B3, 49, 8D, 64, 24, 2C, E9, D0, F7, FF, FF, 0F, A5, F9, 99, 60, 89, EC, 27, 66, 81, EF, CB, AC, 66, 0F, BD, ED, 59, 8D, 97, F8, CA, CD, 70, 37, 5A, 66, D3, EE, 5F, 3F, 66, 1D, 05, F7, 84, DB...
 
[+]

Entropy:
7.7307  (probably packed)

Code size:
7 KB (7,168 bytes)

The file gsrld.dll has been seen being distributed by the following 3 URLs.

http://dc544.4shared.com/download/.../gsrld.dll?tsid=20161117-035312-76446aea&sbsr=2a8e5ff6b3f4f2ddcf9a0178ac7b104f98e&lgfp=2000

Remove gsrld.dll - Powered by Reason Core Security