nqrfywoub.dll

Interesting Solutions

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser as well as modify the computer’s system settings that control applications to run on startup. Part of the Injekt brand of unwanted programs. The module nqrfywoub.dll by Interesting Solutions has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Interesting Solutions  (signed and verified)

Version:
1.0.0.1

MD5:
0deabbdd9d61078aeb7d6d190af3ca57

SHA-1:
fa7966b9c6630b00ffb3f3f57cc5e3c86e74997d

SHA-256:
0c94d86179e8aaaab7a90e5e28a028f3193934dbff2db062a1a6f6839835108a

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
5/22/2024 6:50:22 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt (M)
17.2.23.10

File size:
1.4 MB (1,456,616 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2014

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\ProgramData\ztafurmmrjb\dat\nqrfywoub.dll

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/18/2015 10:00:00 PM

Valid to:
4/19/2016 8:59:59 PM

Subject:
CN=Interesting Solutions, O=Interesting Solutions, L=St. James, S=St. James, C=BB

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
65BAC0C20EBC1780150DDA8808B0161A

File PE Metadata
Compilation timestamp:
3/14/2015 1:27:40 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x2A18

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, FF, 2B, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, A7, FE, FF, FF, CC, CC, CC, 48, 89, 4C, 24, 08, 48, 81, EC, 88, 00, 00, 00, 48, 8D, 0D, 55, C6, 00, 00, FF, 15, 87, 76, 00, 00, 48, 8B, 05, 40, C7, 00, 00, 48, 89, 44, 24, 58, 45, 33, C0, 48, 8D, 54, 24, 60, 48, 8B, 4C, 24, 58, E8, FB, 4B, 00, 00, 48, 89, 44, 24, 50, 48, 83, 7C, 24...
 
[+]

Code size:
34 KB (34,816 bytes)

Remove nqrfywoub.dll - Powered by Reason Core Security