nsprocess.dll

Fedorov Paul

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The module nsprocess.dll by Fedorov Paul has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
Fedorov Paul  (signed and verified)

MD5:
9e894b99a60ce2e4fad6f52ba563ade4

SHA-1:
711462f633b252a0ee895c3e4f28836fad043e34

SHA-256:
f34c22c9547d7b112cd9485c1b4edaf939989b0f0e8ac5c84f672b1774f4ab2a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 3:33:41 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Webpick (M)
16.7.29.14

File size:
11.3 KB (11,616 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\nsprocess.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
11/7/2014 6:00:00 AM

Valid to:
11/5/2015 5:59:59 AM

Subject:
CN=Fedorov Paul, OU=Individual Developer, O=No Organization Affiliation, L=Saint-Petersburg, S=US Minor Outlying Islands, C=RU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1F1C6CD90A38CE2585B8E44D4C5B4372

File PE Metadata
Compilation timestamp:
6/28/2011 1:48:48 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
192:lsrMS4xYqmsoRks9HtS0Fcou7+wse+PjPon2rfl:l7Ws3Ot7fuSPLonifl

Entry address:
0x1001

Entry point:
33, C0, 40, C2, 0C, 00, 55, 8B, EC, 56, 57, 8B, 7D, 08, 8D, 45, 08, 50, 57, FF, 15, 4C, 20, 00, 10, 8B, 75, 0C, 8B, 45, 08, 3B, 06, 75, 12, 6A, 00, 6A, 00, 6A, 10, FF, 76, 04, FF, 15, 58, 20, 00, 10, 89, 7E, 04, 33, C0, 5F, 40, 5E, 5D, C2, 08, 00, 55, 8B, EC, 83, EC, 0C, 53, 56, 8B, 75, 08, 57, 56, 33, DB, 53, 68, 01, 04, 10, 00, FF, 15, 10, 20, 00, 10, 8B, F8, 3B, FB, 74, 6B, 89, 75, F4, 89, 5D, F8, 39, 5D, 0C, 74, 41, 8D, 45, F4, 50, 68, 07, 10, 00, 10, FF, 15, 50, 20, 00, 10, 39, 5D, F8, 74, 2D, 8D, 45...
 
[+]

Code size:
1.5 KB (1,536 bytes)

Remove nsprocess.dll - Powered by Reason Core Security