How to remove npsafe_surfing.dll.vir
- File Details
- Overview
- Analysis
npsafe_surfing.dll.vir
The module npsafe_surfing.dll.vir has been detected as Adware.Toolbar
File Details
Product Name: |
|
MD5: |
a5fd0edbe993ee18cb338438ec37d432 |
Size: |
176 KB |
First Published: |
2017-05-28 18:12:42 (7 years ago) |
Latest Published: |
2019-07-05 21:32:10 (5 years ago) |
Status: |
Adware.Toolbar (on last analysis) |
|
Analysis Date: |
2019-07-05 21:32:10 (5 years ago) |
%localappdata%\bromium\user data\default\extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\npapi |
%localappdata%\playfree browser\user data\default\extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\npapi |
%appdata%\opera software\opera next\extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\npapi |
%localappdata%\xpom\user data\default\extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\npapi |
%sysdrive%\adwcleaner\quarantine\files\mkvgidoedsvadbgmqkschaerykghhaxs\user data\default\extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\npapi |
%localappdata%\yandex\internet\user data\default\extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\npapi |
%sysdrive%\adwcleaner\quarantine\files\pxkdizxckjutpypclicdrxdbsoqkzpbv\user data\default\extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\npapi |
%localappdata%\maplestudio\chromeplus\user data\default\extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\npapi |
%localappdata%\comodo\dragon\user data\default\extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\npapi |
%localappdata%\nichrome\user data\default\extensions\kcknbenjnkkjknphmnidanjifbgphjke\14.18_0\npapi |
npsafe_surfing.dll |
npsafe_surfing.dll.vir |
|
47.2% |
|
|
34.0% |
|
|
4.5% |
|
|
4.2% |
|
|
4.2% |
|
|
3.1% |
|
|
1.7% |
|
|
1.0% |
|
Windows 7 |
65.4% |
|
Windows 10 |
20.8% |
|
Windows 8 |
5.5% |
|
Windows XP |
4.5% |
|
Windows 8.1 |
3.8% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x10000000 |
Entry Address: |
0x0000fbb5 |
Name |
Size of data |
MD5 |
.text |
117248 |
ca229a4d9fa455a4448e568d906c2a98 |
.rdata |
46592 |
65150e929a7b787d6939a2da2716dc5f |
.data |
5632 |
61b8e01f15ec678005d6aaa999add40f |
.rsrc |
1536 |
e52c58b3c2a7cd03fbe771ba8ac3eb34 |
.reloc |
8704 |
091572852f6032bf0ea65882bac10497 |