plusmat5.dll

TODO:

PioneerSoft

The module plusmat5.dll, “TODO: <File description>” by PioneerSoft has been detected as adware by 2 anti-malware scanners.
Publisher:
TODO: <Company name>  (signed by PioneerSoft)

Product:
TODO: <Product name>

Description:
TODO: <File description>

Version:
1.0.0.1

MD5:
1277167b66529e677ba1b001de1d57ac

SHA-1:
1edd06298727e88356190194bdcd56a244855fe9

SHA-256:
899d6a96e079a820f32bf5b1ef1440974a56e124007e4938adfe119c9a0ef810

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
12/28/2024 8:00:58 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.Adkor.127
9.0.1.0325

Reason Heuristics
PUP.PioneerSoft (M)
15.11.21.17

File size:
477 KB (488,416 bytes)

Product version:
1.0.0.1

Copyright:
TODO: (c) <Company name>. All rights reserved.

Original file name:
usewill.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\lemonwebtoon\plusmat5.dll

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
5/11/2015 6:19:37 PM

Valid to:
6/15/2016 5:50:18 PM

Subject:
CN=PioneerSoft, O=PioneerSoft, L=Yongin-si, S=Gyeonggi-do, C=KR

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F8AC02AF8C0A421D8579F3A805C55084

File PE Metadata
Compilation timestamp:
11/17/2015 5:14:55 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:YZ1zhllQpdd2clSMdFV7So7fyRFDJyMFqKsSHsce3qf9Ozsu7FzOeOym:8NhUdFdwFDJVFqMHscbfQsuAHym

Entry address:
0x2B621

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, F2, A5, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 6A, 0C, 68, A8, FC, 05, 10, E8, DC, 2B, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, C8, BF, 06, 10, 77, 22, 6A, 04, E8, EE, 91, 00, 00, 59, 83, 65, FC, 00, 56, E8, F5, 99, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, E8, 2B, 00, 00, C3, 6A, 04, E8, E9, 90, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87...
 
[+]

Entropy:
6.3595

Code size:
316.5 KB (324,096 bytes)

Remove plusmat5.dll - Powered by Reason Core Security