wzshellctx64.dll

Yang Liu

The module wzshellctx64.dll by Yang Liu has been detected as a potentially unwanted program by 3 anti-malware scanners.
Publisher:
Yang Liu  (signed and verified)

MD5:
85904a2a9f301f12be4c7945df0d61ae

SHA-1:
5fcae7d4c4a4e797f1f820aca81261131fc54cf5

SHA-256:
c4c0205fdc7fbd4fff9e5d0580f76c63a36342d77e650037c5c3d4dc75f62226

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 3:39:45 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Could be an adware Qksee
2013.0.4477

Dr.Web
Adware.Mutabaha.1195
9.0.1.05190

Microsoft Security Essentials
Trojan:Win32/Xadupi
1.229.1483.0

File size:
197.1 KB (201,848 bytes)

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\Program Files\winzipper\wzshellctx64.dll

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
4/18/2016 9:00:00 PM

Valid to:
11/25/2016 9:59:59 PM

Subject:
CN=Yang Liu, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6F245CD10782C354F8265551BE5F41E0

Registration
CLSID:
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}

COM registered:
Yes

File PE Metadata
Compilation timestamp:
4/18/2016 11:39:57 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:aBHULevBnQXC1xQpPzHLH03nUslb/3VuiO37KfrFNGdR5xuBxgD9K9UN:OHULe5nQGyPzT03nHlb/3VuTKTFa

Entry address:
0xB28C

Code size:
89 KB (91,136 bytes)

Approved Shell Extension
Name:
WinZipper Shell Extension

CLSID:
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}

CLSID name:
wzShellContextMenu Class


Remove wzshellctx64.dll - Powered by Reason Core Security