How to remove PotPlayer64.dll

PotPlayer64.dll

The module PotPlayer64.dll has been detected as Trojan.Heur!

PotPlayer64.dll

PotPlayer64.dll is a Windows file recorded in the ThreatInfo database. It is associated with Street. The reported company name is Kakao. The current detection status is Trojan.Heur!, based on the latest analysis from 2021-11-19 21:31:05 (4 years ago).

If PotPlayer64.dll appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Heur!.

Product Name: Street
Company Name: Kakao
MD5: 45e99fc3f44d115e961d391a9d96779e
Size: 22 MB
First Published: 2021-11-19 21:31:05 (4 years ago)
Latest Published: 2021-11-19 21:31:05 (4 years ago)
Status: Trojan.Heur! (on last analysis)
Analysis Date: 2021-11-19 21:31:05 (4 years ago)
Signed By: Kakao corp.
Status: Invalid (digital signature could be stolen or file could be patched)

The signature on PotPlayer64.dll is not reported as trusted and valid. Invalid or suspicious signature data can indicate tampering, repackaging, or an unrelated file using copied publisher information.

%programfiles%

ThreatInfo has observed PotPlayer64.dll in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Russian Federation with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 7 100.0%

The most common operating system signal for PotPlayer64.dll is Windows 7 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

PotPlayer64.dll is identified as pe for 64 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000180000000
Entry Address: 0x00be2f58

PE Sections:

Name Size of data MD5
.text 14078976 10d0aeeec5cfaf556cc38e838e62d285
.text.un 34304 86a6f0075708437789a378fb4d3cb032
.rotext 512 7928fa4d5bd757b539a2c0f9680cb6a3
.rdata 7389696 ca6bbb3acc8a9c64e1501e42b5b760dd
.data 453120 e4cd53b4e9b483e29d0fefb54486693a
.pdata 477184 5fc538f4b31e1fb4a3b64031fd614d0d
.xdata.u 512 6cb790349b3394e110508bd7806b2f20
.pdata.u 512 a55204773e9c71b5d027d40da3099ddc
.drectve 1536 1028622dd52119a2d5e38b2669eea60a
.rodata 512 efa56ce9354cdde33479079f042eb3d7
_RDATA 14336 90ba0c2e43eec27f2ae7b0c8e34767bb
.rsrc 687616 e01901306556ff87f7ca14802e154824
.reloc 230912 62f5f9e575c81c70b9717b30fa78006a

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information:

Download GridinSoft Anti-Malware - Removal tool for PotPlayer64.dll