nfymg.dll

The module nfymg.dll has been detected as a potentially unwanted program by 16 anti-malware scanners. According to AVG, this software downloads additional adware offers during setup.
MD5:
e935d34757aa919ef882cad71686a5af

SHA-1:
6cadacf787ddc0df6359b8ce597688c3d68dfa92

SHA-256:
d7ee09a02d27aa8b42fba983fbdbc035a92a97b1949ffd2dc3086a704d8f6a80

Scanner detections:
16 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/27/2024 12:35:49 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.1227189
562

Avira AntiVirus
PUA/Outbrowse.Gen
3.6.1.96

avast!
Win32:Malware-gen
2014.9-150421

AVG
Downloader
2016.0.3133

Baidu Antivirus
PUA.Win32.OutBrowse
4.0.3.15421

Emsisoft Anti-Malware
Adware.Generic.1227189
8.15.07.22.12

ESET NOD32
Win32/OutBrowse.BY potentially unwanted application
9.7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
4/21/2015

F-Prot
W32/OutBrowse.N
v6.4.6.5.141

F-Secure
Adware.Generic.1227189
11.2015-22-07_4

herdProtect (fuzzy)
2015.7.22.12

K7 AntiVirus
Adware
13.202.15636

McAfee
Artemis!E935D34757AA
5600.6789

Reason Heuristics
Threat.Win.Reputation.IMP
15.4.21.1

Trend Micro House Call
Suspicious_GEN.F47V0417
7.2.111

VIPRE Antivirus
Threat.4150696
39354

File size:
126.5 KB (129,536 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\nfymg.dll

File PE Metadata
Compilation timestamp:
4/18/2015 1:10:09 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
1536:/GP/c6nfm5Ms9s+10/p5Z6aD5oVFkIAXOxKduXmbc9lInrijnQjqnAqCMK/aCXWM:SEfZsu0/pD5oV+wccemntCMKSkWS2

Entry address:
0x75A5

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, DB, 60, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8, 03, EC, FF, FF, 59, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 45, 08, 56, 8B, F1, C6, 46, 0C, 00, 85, C0, 75, 63, E8, EB, 39, 00, 00, 89, 46, 08, 8B, 48, 6C, 89, 0E, 8B, 48, 68, 89, 4E, 04, 8B, 0E, 3B, 0D, 28, F2, 01, 10, 74, 12, 8B, 0D, E0, EF, 01, 10, 85, 48, 70, 75, 07, E8, A7...
 
[+]

Code size:
91 KB (93,184 bytes)

Remove nfymg.dll - Powered by Reason Core Security