uiahelper.dll

EduIQ.com Damjan Kriznik s.p.

Publisher:
EduIQ.com Damjan Kriznik s.p.  (signed and verified)

MD5:
e2cfe8fe9374f9a59226cfe0dd9d6c2a

SHA-1:
b008c524c9427dfe8919f7f73da6d0274eaef73e

SHA-256:
3fc4bc60574e74b355622048969be291fccadbdb4967d18944677339c89fdcbe

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/28/2024 5:39:13 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

File size:
115.6 KB (118,343 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\classroom spy pro\bin\uiahelper.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/6/2012 5:00:00 PM

Valid to:
8/7/2014 4:59:59 PM

Subject:
CN=EduIQ.com Damjan Kriznik s.p., O=EduIQ.com Damjan Kriznik s.p., STREET=Slovenja vas 2D, L=HAJDINA, S=SLOVENIA, PostalCode=2288, C=SI

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C6910D557A2D6EB49458799D35EABFAC

File PE Metadata
Compilation timestamp:
9/7/2013 5:11:47 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:SoS6U9GdiO09NzAhUD3sTN2s+zheW6BVrqzCJ3bdDY+W14N4NmzWlIA7hKRQxDkV:SoaO2NzHm2lQBV+UdE+rECWp7hK4DkV

Entry address:
0x1411

Entry point:
E9, 59, 26, 00, 00, 83, 7D, 0C, 01, 75, 05, E8, 18, 14, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 40, 9C, 00, 10, 89, 0D, 3C, 9C, 00, 10, 89, 15, 38, 9C, 00, 10, 89, 1D, 34, 9C, 00, 10, 89, 35, 30, 9C, 00, 10, 89, 3D, 2C, 9C, 00, 10, 66, 8C, 15, 58, 9C, 00, 10, 66, 8C, 0D, 4C, 9C, 00, 10, 66, 8C, 1D, 28, 9C, 00, 10, 66, 8C, 05, 24, 9C, 00, 10, 66, 8C, 25, 20, 9C, 00, 10, 66, 8C, 2D, 1C, 9C, 00, 10, 9C, 8F, 05, 50, 9C...
 
[+]

Entropy:
7.4949

Packer / compiler:
Xtreme-Protector v1.05

Code size:
18 KB (18,432 bytes)

Scan uiahelper.dll - Powered by Reason Core Security