nsdialogs.dll

Xi'an TingXue Network Technology co., Ltd.

nsdialogs.dll is the nsDialogs allows creation of custom pages in the NSIS (Nullsoft Installer) setup program used by many installers, nsDialogs can create pages with any type of controls and runs as a common NSIS plug-in and is recompiled by Xi'an TingXue Network Technology co., Ltd..
Publisher:

MD5:
c2b17d9b25d5b07d2b87d91d42443699

SHA-1:
8cc10797ddacd0c4ddbc796110751d0fdfc91e84

SHA-256:
2c4915ce21c754810fe85063e0a4b8460bf0151b56a5379e1a9635010f4f71ac

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 11:55:06 PM UTC  (a few moments ago)

File size:
17.2 KB (17,600 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\nsdialogs.dll

Digital Signature
Authority:
WoSign CA Limited

Valid from:
5/6/2015 5:35:18 PM

Valid to:
5/6/2016 6:35:18 PM

Subject:
CN="Xi'an TingXue Network Technology co., Ltd.", O="Xi'an TingXue Network Technology co., Ltd.", L=Xi'an, S=Shaanxi, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
335183F94C563B4721865B606129EFBA

File PE Metadata
Compilation timestamp:
6/7/2009 5:41:25 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
192:a6n+0SAfRE+/8ZYxldqn420+ogLE1KUlpXNh/bqxLhMdBVXP:aE+0S8vxldN20+fLEQyXNh/bqxlMdLf

Entry address:
0x1CF2

Entry point:
8B, 44, 24, 04, A3, A4, 50, 00, 10, 33, C0, 40, C2, 0C, 00, E8, BC, 02, 00, 00, A3, CC, 50, 00, 10, C3, 55, 8B, EC, 83, 3D, CC, 50, 00, 10, 00, 0F, 84, 9D, 00, 00, 00, 8B, 45, 08, 56, 57, 8B, 7D, 10, 83, F8, 01, 74, 64, 6A, 02, 5E, 3B, C6, 74, 50, 83, F8, 04, 7E, 45, 83, F8, 06, 7E, 46, 83, F8, 07, 74, 18, 83, F8, 08, 74, 49, 83, F8, 09, 75, 31, 8B, 45, 0C, 83, 08, 40, 81, 0F, 00, 10, 40, 00, EB, 5C, 8B, 4D, 0C, 8B, 01, 8B, D0, 83, E2, 1F, 74, 11, 83, FA, 0C, 74, 0C, 83, FA, 03, 75, 46, 80, CC, 02, 89, 01...
 
[+]

Entropy:
6.5225

Code size:
4.5 KB (4,608 bytes)

Scan nsdialogs.dll - Powered by Reason Core Security