hvm.dll

DNGuard HVM Runtime Library

Digiarty, Inc.

The library hvm.dll has been detected as malware by 3 anti-virus scanners.
Publisher:
ZiYuXuan Studio  (signed by Digiarty, Inc.)

Product:
DNGuard HVM Runtime Library

Version:
3, 7, 2, 1

MD5:
9ee66dac11eccc08718ad992090bf9b2

SHA-1:
9b077561977bab222090a18681ab9f5252bb48b0

SHA-256:
9eb17d03bc6b01274f7f89cf55450aa8ce0b917b4a106b4e7df613db83157414

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
12/25/2024 12:42:41 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.16.24

File size:
986.3 KB (1,010,007 bytes)

Product version:
3, 7, 2, 1

Copyright:
Copyright (C) 2006 - 2014 All rights reserved

Trademarks:
DNGuard

Original file name:
HVMRuntm.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\dearmob\5kplayer\hvm.dll

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
1/6/2016 4:00:00 PM

Valid to:
9/23/2018 4:59:59 PM

Subject:
CN="Digiarty, Inc.", O="Digiarty, Inc.", L=ChengDu, S=Sichuan, C=CN

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
0DDD683D630AA770B5187C7F038BA4B7

File PE Metadata
Compilation timestamp:
3/20/2016 7:11:58 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x1C601

Entry point:
E9, E9, B1, FF, FF, 75, 05, E8, 0D, 70, 00, 00, FF, 74, 24, 04, 8B, 4C, 24, 10, 8B, 54, 24, 0C, E8, ED, FE, FF, FF, 59, C2, 0C, 00, CC, CC, 68, B0, A1, 01, 60, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, D0, 9C, 03, 60, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, CC, CC, CC, 8B...
 
[+]

Entropy:
7.0205

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
800 KB (819,200 bytes)

Remove hvm.dll - Powered by Reason Core Security