nsdialogs.dll

Xi'an TingXue Network Technology co., Ltd.

nsdialogs.dll is the nsDialogs allows creation of custom pages in the NSIS (Nullsoft Installer) setup program used by many installers, nsDialogs can create pages with any type of controls and runs as a common NSIS plug-in and is recompiled by Xi'an TingXue Network Technology co., Ltd..
Publisher:

MD5:
6deda89daa3aaa2a61773ce4e114da0a

SHA-1:
e5f052562acd08ada5be0062b47ad50d634f7a22

SHA-256:
43a1ad4d2c9451351f12578fc47c273f6f2f6a6c3bf4b41927eb2485ee5d8223

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
2/25/2025 8:58:35 PM UTC  (today)

File size:
26.8 KB (27,488 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\nsdialogs.dll

Digital Signature
Authority:
WoSign CA Limited

Valid from:
1/21/2016 1:41:37 AM

Valid to:
5/21/2016 2:41:37 AM

Subject:
CN="Xi'an TingXue Network Technology co., Ltd.", O="Xi'an TingXue Network Technology co., Ltd.", L=Xi'an, S=Shaanxi, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
5451A8E67DCCD396C3BEF61E2EF9A151

File PE Metadata
Compilation timestamp:
6/6/2009 5:41:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
384:UE+0S8vxldN206mQmxlM2zailXGvL0CB4El3jxQmaqI8zailXGvL0CB4EaU/:Ab8v3Hp1o2zOL0GP5aqI8zOL0GEO

Entry address:
0x1CF2

Entry point:
8B, 44, 24, 04, A3, A4, 50, 00, 10, 33, C0, 40, C2, 0C, 00, E8, BC, 02, 00, 00, A3, CC, 50, 00, 10, C3, 55, 8B, EC, 83, 3D, CC, 50, 00, 10, 00, 0F, 84, 9D, 00, 00, 00, 8B, 45, 08, 56, 57, 8B, 7D, 10, 83, F8, 01, 74, 64, 6A, 02, 5E, 3B, C6, 74, 50, 83, F8, 04, 7E, 45, 83, F8, 06, 7E, 46, 83, F8, 07, 74, 18, 83, F8, 08, 74, 49, 83, F8, 09, 75, 31, 8B, 45, 0C, 83, 08, 40, 81, 0F, 00, 10, 40, 00, EB, 5C, 8B, 4D, 0C, 8B, 01, 8B, D0, 83, E2, 1F, 74, 11, 83, FA, 0C, 74, 0C, 83, FA, 03, 75, 46, 80, CC, 02, 89, 01...
 
[+]

Entropy:
7.0213

Code size:
4.5 KB (4,608 bytes)

Scan nsdialogs.dll - Powered by Reason Core Security