NP52Stub.DLL

MindSpark Toolbar Platform Plugin Stub

Mindspark Interactive Network

This library is part of the Mindspark toolbar which uses the Ask.com search property to install a web browser extension and modify the browser's search, home and new tab features in order to redirect web searches to the IAC property. The module NP52Stub.DLL, “MindSpark Toolbar Platform Plugin Stub for 32-bit Windows” by Mindspark Interactive Network has been detected as a potentially unwanted program by 18 anti-malware scanners. It is installed within the Mozilla Firefox web browser as an extension/plugin as ‘@Webfetti_52.com/Plugin’.
Publisher:
MindSpark  (signed by Mindspark Interactive Network)

Product:
MindSpark Toolbar Platform Plugin Stub

Description:
MindSpark Toolbar Platform Plugin Stub for 32-bit Windows

Version:
1, 0, 1, 1

MD5:
031758d51af7d92a73d04d23e0c3bc46

SHA-1:
d83d65af4900618385ee44ad96f59ca3123b61c4

SHA-256:
2aaebec7966c58671ce16514c98f784852e83de009402a22e4327f6b20f0def4

Scanner detections:
18 / 68

Status:
Potentially unwanted

Explanation:
Part of the MyWebSearch/Mindspark/Ask web browser extension and toolbar.

Analysis date:
4/19/2024 11:43:42 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.MyWebSearch
7.1.1

avast!
Win32:Mindspark-A [PUP]
2014.9-151127

AVG
Toolbar.MyWebSearch.D
2016.0.2913

Baidu Antivirus
Adware.Win32.MyWebSearch
4.0.3.151127

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
9.0.1.0331

ESET NOD32
Win32/Toolbar.MyWebSearch.T potentially unwanted
9.11536

F-Prot
W32/A-4763620f
v6.4.7.1.166

G Data
Win32.Adware.Mindspark
15.11.25

Kaspersky
not-a-virus:WebToolbar.Win32.Agent
14.0.0.1059

Malwarebytes
PUP.Optional.Mindspark.A
v2015.11.27.04

Panda Antivirus
Adware/WebSearch
15.11.27.04

Quick Heal
PUA.Webwatcher.OD5
11.15.14.00

Reason Heuristics
PUP.MyWebSearch.Mindspark.Toolbar (M)
15.11.27.4

Rising Antivirus
PE:Trojan.Win32.Generic.157D441B!360530971
23.00.65.151125

SUPERAntiSpyware
Adware.Mindspark/Variant
9483

VIPRE Antivirus
39708

Zillya! Antivirus
Adware.WebSearch.Win32.171
2.0.0.2155

File size:
30.4 KB (31,096 bytes)

Product version:
2, 3, 0, 0

Copyright:
Copyright © 2005, 2006, 2007, 2008, 2009, 2010, 2011

Original file name:
NP52Stub.DLL

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\webfetti_52\bar\1.bin\np52stub.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/9/2012 5:00:00 PM

Valid to:
5/6/2015 4:59:59 PM

Subject:
CN=Mindspark Interactive Network, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Mindspark Interactive Network, L=White Plains, S=NewYork, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
098417F7EA6406EC7B320590E17A65B7

File PE Metadata
Compilation timestamp:
5/12/2011 11:56:33 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
192:wu+ww1b4KcJ4PWtSeMWhJnYe+PjPc+rO4dj+vyge8r9ZCspE+TM4rmz1214g:6b4XiWtzMWHnYPLcHuVteMoD

Entry address:
0x10B3

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 56, 8B, 75, 08, 75, 0B, 89, 35, CC, 30, 00, 10, E8, 20, 00, 00, 00, FF, 75, 10, FF, 75, 0C, 56, E8, 47, 02, 00, 00, 83, 7D, 0C, 00, 8B, F0, 75, 05, E8, 3E, 00, 00, 00, 8B, C6, 5E, 5D, C2, 0C, 00, 68, A8, 30, 00, 10, FF, 15, 40, 20, 00, 10, 68, 14, 30, 00, 10, 68, 00, 30, 00, 10, E8, 03, 00, 00, 00, 59, 59, C3, 56, 8B, 74, 24, 08, 3B, 74, 24, 0C, 73, 0D, 8B, 06, 85, C0, 74, 02, FF, D0, 83, C6, 04, EB, ED, 5E, C3, A1, C8, 30, 00, 10, 85, C0, 74, 2F, 8B, 0D, C4, 30, 00, 10, 56, 8D...
 
[+]

Entropy:
3.0260

Developed / compiled with:
Microsoft Visual C++

Code size:
4 KB (4,096 bytes)

Mozilla Plugin
Name:
@Webfetti_52.com/Plugin


Remove NP52Stub.DLL - Powered by Reason Core Security