nfapi.dll

TRIORIS LLC

The module nfapi.dll by TRIORIS has been detected as a potentially unwanted program by 3 anti-malware scanners.
Publisher:
TRIORIS LLC  (signed and verified)

MD5:
89bd9631fc462700bb894edb67984f0f

SHA-1:
29ca25eba1222335617c2f84769d0baf655bfccb

SHA-256:
703c9624538f94fb13ba4a532d2dfd5b1c71684ec66886e860733f80b5ada9b7

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
5/10/2024 4:59:58 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.NetFilter
4.0.3.141024

ESET NOD32
Win32/AdWare.Trioris (variant)
8.10597

Reason Heuristics
PUP.Optional.TRIORIS.F
14.10.24.2

File size:
84.2 KB (86,176 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\screentk\nfapi.dll

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/27/2013 4:00:00 AM

Valid to:
3/27/2016 3:59:59 AM

Subject:
CN=TRIORIS LLC, O=TRIORIS LLC, STREET="Griboedova str., 34, 5", L=Novosibirsk, S=Novosibirsk region, PostalCode=630000, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00DDE431469F44EE01CD42B3680AB9990D

File PE Metadata
Compilation timestamp:
8/4/2014 1:12:13 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:vESanc+yBBERjhJTChK22Lk7Iak5ZboshbgbQteVlrv:vAyBBElhJTCh8oI/Zbos6QtC9

Entry address:
0x571B

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 5A, 29, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, C0, 2F, 01, 10, 89, 0D, BC, 2F, 01, 10, 89, 15, B8, 2F, 01, 10, 89, 1D, B4, 2F, 01, 10, 89, 35, B0, 2F, 01, 10, 89, 3D, AC, 2F, 01, 10, 66, 8C, 15, D8, 2F, 01, 10, 66, 8C, 0D, CC, 2F, 01, 10, 66, 8C, 1D, A8, 2F, 01, 10, 66, 8C, 05, A4, 2F, 01, 10, 66, 8C, 25, A0, 2F, 01, 10, 66, 8C, 2D, 9C, 2F, 01, 10, 9C, 8F, 05, D0, 2F...
 
[+]

Code size:
50 KB (51,200 bytes)

Remove nfapi.dll - Powered by Reason Core Security