Gridinsoft Logo
File Icon

FMediaLibraryView.dll Trojan Packed Analysis

Technical Analysis

File Name FMediaLibraryView.dll
File Type
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Scanner Version 1.0.181.174
Database Version 2024-07-07 00:00:24 UTC

Trojan.Win64.Packed.cl

Malware family: Packed

Packed malware uses compression, encryption, or obfuscation techniques to alter code appearance and evade security detection. These methods modify the original malware structure to bypass signature-based detection systems and complicate analysis efforts.
N/A
Detection Rate
8,238,616
File Size (bytes)
2024-07-07
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
9c95bb879b15e54eff514aa2b022f445
SHA1
9e9c943c3dd7178f1071ad775ab92e0bf22c0854
SHA256
ed94dad0e2dd00be12d8d8053006e38587c59f836937adba12b039c3c28f600b
SHA512
a635d932c3a903973c71f202427f9c795ad2f57b1ee6000d2bb8579c91d3cb4e2f8918e627dc190d22815411704f791ab5c36da530c5c0a57b9730de9298a490
ImpHash
a96a5ebb1bb01ec4667a7500db07343e

PE Analysis

Basic Information

Icon
Hash: a4c09c4859e5ebf0c25d5741e4dcf096
Fuzzy: f3a8cd694b22d7e9f267a395d00d9ba9
dHash: c69a727219ccb2b2
Image Base 0x180000000
Entry Point 0x180e81058
Compilation Time 2024-05-13 06:37:38
Checksum 0x007e564e (Actual: 0x007e564e)
OS Version 6.0
PEiD Signatures PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 32 libraries
Exports 1774 functions
Resources 12 Resources
Sections 13 Sections

Version Information

CompanyName Wondershare
FileDescription FMediaLibraryView
FileVersion 13, 3, 12, 7152
InternalName FMediaLibraryView
LegalCopyright Copyright (c) 2020-2024 Wondershare. All rights reserved.
OriginalFilename FMediaLibraryView
ProductName FMediaLibraryView
ProductVersion 13.3.12.7152
Translation 0x0804 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
0x00001000 3,847,337 bytes 1,261,568 bytes 7.99 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 5A128DD0A5F192DAFAC914C597F0C172
0x003ad000 1,827,788 bytes 463,872 bytes 7.95 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ C3D28D05392E0DDD0E991A973CEE7501
0x0056c000 104,928 bytes 23,040 bytes 7.95 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE E423EBFAB94BD1E83F0BAD20164F4569
0x00586000 226,152 bytes 141,312 bytes 7.75 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B04F852F3C797DF60178C6C9FB2DF274
0x005be000 196,416 bytes 55,808 bytes 7.95 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ BF520A3A21FC55916DD72F9F5CA93E5A
0x005ee000 50,904 bytes 19,968 bytes 7.50 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 5F5C734270A86CF7D170AF531D06E31C
.edata 0x005fb000 130,560 bytes 130,560 bytes 5.66 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B6A4173DC774F018CC542D71866ADB89
.idata 0x0061b000 4,096 bytes 3,072 bytes 4.66 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE B49F11F6824341354A0A2E70D0DC4303
.tls 0x0061c000 4,096 bytes 512 bytes 0.28 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE F1F66AD376A0EE6E48829000D1CBB256
.rsrc 0x0061d000 196,608 bytes 196,608 bytes 5.95 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B1FE636C0EB048750C5AF4AF70F989CC
.themida 0x0064d000 8,601,600 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.boot 0x00e81000 5,921,792 bytes 5,921,792 bytes 7.95 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 37CC54F3C4692F18E2B71272D18CE0E3
.reloc 0x01427000 4,096 bytes 16 bytes 2.47 (Normal) IMAGE_SCN_MEM_READ 912E040113ADC71A247B5129D8D1D633
Entropy Analysis Alert

7 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 12 (195,682 bytes)
Resource Type Count Total Size Percentage
RT_ICON 9 194,325 bytes
99.3%
RT_GROUP_ICON 1 132 bytes
0.1%
RT_VERSION 1 844 bytes
0.4%
RT_MANIFEST 1 381 bytes
0.2%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win64.Packed.cl Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win64.Packed.cl without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware