nssckbi.dll

Network Security Services

Sendori, Inc

This is part of the Sendori web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. nssckbi.dll is the Mozilla Network Security Services (NSS) library that provides access to a list of trusted root CA certificates that are distributed with Mozilla software and is recompiled by Sendori, Inc. The library nssckbi.dll, “NSS Builtin Trusted Root CAs” by Sendori, Inc has been known to be a potentially unwanted program that has been detected by 1 anti-malware scanner. Note, this is a common distributed file and although it has been detected it might not be a threat is un-coupled from its distribution source.
Publisher:
Mozilla Foundation  (signed by Sendori, Inc)

Product:
Network Security Services

Description:
NSS Builtin Trusted Root CAs

Version:
1.91

MD5:
cbd2eea6d8ded510f758fd45978bf34d

SHA-1:
6abebbcb1fe51899d74453c2d1dff78cd3d4d3b4

SHA-256:
a937ddcbd0e53963e8d92607c4305f3833f279087fab838d27c5516c864af02d

Scanner detections:
1 / 68

Status:
Inconclusive but possibly unwanted  (It is part of a common redistributable library)

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 12:32:04 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Common.PartOf.PUP.Sendori.MozillaFoundation (M)
15.12.25.23

File size:
413.8 KB (423,712 bytes)

Product version:
1.91

Original file name:
nssckbi.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\sendori\nssckbi.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/11/2012 7:00:00 PM

Valid to:
4/4/2013 6:59:59 PM

Subject:
CN="Sendori, Inc", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Sendori, Inc", L=Oakland, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
28FA9F749BFC21C3FDFCFEFB6497011B

File PE Metadata
Compilation timestamp:
9/12/2012 8:07:04 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:mJz2s9oBgdMTWfpUwFygo5zUM38MEuL9ewNkUE0kUq4:Gf9OgWTWfpf0gmzY49zNkUE0kUq4

Entry address:
0xEC51

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 6B, 1D, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A4, 01, 00, 00, 81, F9, 00, 01, 00, 00, 72, 1F, 83, 3D, 04, 3B, 06, 10, 00, 74, 16, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 08, 5E, 5F, 5D, E9, 22, 1E, 00, 00, F7, C7, 03, 00, 00, 00, 75, 15, C1, E9...
 
[+]

Entropy:
6.8965

Code size:
79.5 KB (81,408 bytes)

Scan nssckbi.dll - Powered by Reason Core Security