googlechromeremoteplugin.dll

GoogleChromeRemotePlugin

Veristaff. Com Ltd

The module googlechromeremoteplugin.dll by Veristaff. Com has been detected as adware by 6 anti-malware scanners. This file is typically installed with the program Yahoo Community Smartbar by Linkury Inc. which is a potentially unwanted software program.
Publisher:
Veristaff. Com Ltd  (signed and verified)

Product:
GoogleChromeRemotePlugin

Description:
nprt

Version:
1, 0, 0, 1

MD5:
899e5b87be5330a3720c048db2dc42ad

SHA-1:
22f878e941433a2e1b436ec5f38466f509e5bceb

SHA-256:
6b4745d0eb38f5ad672d753b7b9f7e277cf45c709ff71f24924bbc636f665521

Scanner detections:
6 / 68

Status:
Adware

Analysis date:
4/23/2024 4:27:43 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.Linkury
7.1.1

AVG
Generic
2015.0.3365

ESET NOD32
Win32/Toolbar.Linkury.D potentially unwanted application
7.0.302.0

NANO AntiVirus
Riskware.Win32.Linkury.ddpups
0.28.2.61861

Reason Heuristics
PUP.VeristaffCom.Y
14.9.1.2

VIPRE Antivirus
Threat.4150696
32210

File size:
164.6 KB (168,568 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright © 1999

Original file name:
nprt.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\smartbar\application\amfclgbdpgndipgoegfpkkgobahigbcl\googlechromeremoteplugin.dll

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/14/2014 2:37:25 PM

Valid to:
7/15/2015 2:37:25 PM

Subject:
CN=Veristaff. Com Ltd, O=Veristaff. Com Ltd, L=Herzliya, S=Herzliya, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121327C47596D5E76D675A39A539249C1B5

File PE Metadata
Compilation timestamp:
2/27/2013 2:39:05 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:JHSpZO6SL37VU8PevV6fnwA9/Pnnhvfx4ZceAi6xz/WhF75WrgURzjAx6:sufnN9fsHAtxz/IydM

Entry address:
0xB42C

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 3A, 7D, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 58, 54, 02, 10, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 5C, 54, 02, 10, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, 57, 57, 00, 00, 85, C0, 75, 06, B8, C0, 55, 02, 10, C3, 83, C0, 08, C3, E8, 44, 57, 00, 00, 85, C0, 75...
 
[+]

Entropy:
6.4448

Code size:
115.5 KB (118,272 bytes)

The file googlechromeremoteplugin.dll has been discovered within the following program.

Yahoo Community Smartbar  by Linkury Inc.
Yahoo Community Smartbar is a web browser toolbar and extension that modifies the browsers search and home pages as well as delivers contextual based advertising. This toolbar currently supports Internet Explorer, Firefox and Chrome.
www.linkury.com/index-8_faq.html
83% remove it
 
Powered by Should I Remove It?

Remove googlechromeremoteplugin.dll - Powered by Reason Core Security