NP6xEISb.DLL

ReadingFanatic Installer Plugin Stub

Mindspark Interactive Network

This library is part of the Mindspark toolbar which uses the Ask.com search property to install a web browser extension and modify the browser's search, home and new tab features in order to redirect web searches to the IAC property. The module NP6xEISb.DLL, “ReadingFanatic Installer Plugin Stub for 32-bit Windows” by Mindspark Interactive Network has been detected as a potentially unwanted program by 20 anti-malware scanners.
Publisher:
ReadingFanatic  (signed by Mindspark Interactive Network)

Product:
ReadingFanatic Installer Plugin Stub

Description:
ReadingFanatic Installer Plugin Stub for 32-bit Windows

Version:
1,2,11,2

MD5:
ca57f9d06cbcebddeb430dde19c8d649

SHA-1:
07d2dca03e5a66ec16f26a341ea88f0a23a382b1

SHA-256:
0ae75119de24ba26b1790e213adc6fe06a1f7f46694bcfbeaef1e733367897e3

Scanner detections:
20 / 68

Status:
Potentially unwanted

Explanation:
Part of the MyWebSearch/Mindspark/Ask web browser extension and toolbar.

Analysis date:
4/19/2024 2:21:01 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.MyWebSearch
7.1.1

AhnLab V3 Security
Adware/Win32.MyWebSearch
2014.11.22

avast!
Win32:Mindspark-A [PUP]
2014.9-150201

AVG
MyWebSearch
2016.0.3212

Baidu Antivirus
Adware.Win32.MyWebSearch
4.0.3.1521

Clam AntiVirus
Win.Adware.Mywebsearch-81
0.98/21411

Dr.Web
9.0.1.032

ESET NOD32
Win32/Toolbar.MyWebSearch.AI (variant)
9.10696

Fortinet FortiGate
Riskware/MyWebSearch
2/1/2015

F-Prot
W32/A-301cf6c3
v6.4.7.1.166

G Data
Win32.Adware.Mindspark
15.2.24

Kaspersky
not-a-virus:WebToolbar.Win32.MyWebSearch
14.0.0.2554

NANO AntiVirus
Riskware.Win32.WebSearch.dedjrz
0.28.6.62995

Panda Antivirus
Adware/WebSearch
15.02.01.05

Qihoo 360 Security
Win32/Virus.WebToolbar.ce0
1.0.0.1015

Reason Heuristics
PUP.Installer.Mindspark
15.2.1.5

Rising Antivirus
PE:Trojan.Win32.Generic.157DA494!360555668
23.00.65.15130

Vba32 AntiVirus
WebToolbar.MyWebSearch.rh
3.12.18.2

VIPRE Antivirus
34640

Zillya! Antivirus
2.0.0.1977

File size:
46.4 KB (47,496 bytes)

Product version:
1,2,11,2

Copyright:
Copyright © 2005, 2006, 2007, 2008, 2009

Original file name:
NP6xEISb.DLL

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\readingfanatic_6xei\installr\1.bin\np6xeisb.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/10/2012 1:00:00 AM

Valid to:
5/7/2015 12:59:59 AM

Subject:
CN=Mindspark Interactive Network, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Mindspark Interactive Network, L=White Plains, S=NewYork, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
098417F7EA6406EC7B320590E17A65B7

File PE Metadata
Compilation timestamp:
11/19/2013 8:58:37 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
768:RmudPMi5p/I17DuQhzNGnEEDa7ovyNoRmIjOU4:42oD3Kmuo2Ov

Entry address:
0x1517

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 92, 16, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 5D, E9, 5E, 08, 00, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 40, 9C, 00, 10, 89, 0D, 3C, 9C, 00, 10, 89, 15, 38, 9C, 00, 10, 89, 1D, 34, 9C, 00, 10, 89, 35, 30, 9C, 00, 10, 89, 3D, 2C, 9C, 00, 10, 66, 8C, 15, 58, 9C, 00, 10, 66, 8C, 0D, 4C, 9C, 00, 10, 66, 8C, 1D, 28, 9C, 00, 10, 66, 8C, 05, 24, 9C, 00, 10, 66, 8C, 25, 20, 9C, 00, 10, 66...
 
[+]

Entropy:
6.0581

Code size:
19 KB (19,456 bytes)

Remove NP6xEISb.DLL - Powered by Reason Core Security