MFC90U.DLL

Microsoft Visual Studio 2008

LionSea Software co., ltd

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The module MFC90U.DLL, “MFCDLL Shared Library - Retail Version” by LionSea Software co., ltd has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by LionSea Software co., ltd)

Product:
Microsoft® Visual Studio® 2008

Description:
MFCDLL Shared Library - Retail Version

Version:
9.00.30729.01

MD5:
f24b9170328017840b4ad3a31204bf3a

SHA-1:
6ef77c17bcd10fda9b1a4426998b849f76dd2a81

SHA-256:
3fa6a9c4224b689c1b7916c3eca23feee5ea3fa058d94d3f54beaac0506caf14

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 2:17:44 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.LionSea (M)
16.9.26.9

File size:
3.6 MB (3,780,920 bytes)

Product version:
9.00.30729.01

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
MFC90U.DLL

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\wisefixer\mfc90u.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/7/2012 6:00:00 PM

Valid to:
2/7/2013 5:59:59 PM

Subject:
CN="LionSea Software co., ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="LionSea Software co., ltd", L=beijing, S=beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5C82730AFCB40651922D0DB016CEEFF7

File PE Metadata
Compilation timestamp:
7/29/2008 8:07:17 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
98304:9dMcO5ha0BU8ac81wTCx6GgwrPm8LUZMw4ktWkp9pl5fz7kyFLOAkGkzdnEVEFo1:9djO1U8aIdZMY9pcyFLOyEFoKGYo

Entry address:
0x214B77

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, CA, 03, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, C7, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, E8, 51, C4, 78, 89, 0D, E4, 51, C4, 78, 89, 15, E0, 51, C4, 78, 89, 1D, DC, 51, C4, 78, 89, 35, D8, 51, C4, 78, 89, 3D, D4, 51, C4, 78, 66, 8C, 15, 00, 52, C4, 78, 66, 8C, 0D, F4, 51, C4, 78, 66, 8C, 1D, D0, 51, C4, 78, 66, 8C, 05, CC, 51, C4, 78, 66, 8C, 25, C8, 51, C4, 78, 66, 8C, 2D, C4, 51, C4, 78...
 
[+]

Entropy:
7.0038

Code size:
2.4 MB (2,472,448 bytes)

Remove MFC90U.DLL - Powered by Reason Core Security