ntdis_64.dll

Veristaff.com Inc

The module ntdis_64.dll by Veristaff.com Inc has been detected as adware by 9 anti-malware scanners. Additionally, the file is typically installed by a number of programs including LPT System Updater Service by Linkury Ltd. and ShowPass Smartbar by ReSoft Ltd., both potentially unwanted software.
Publisher:
Veristaff.com Inc  (signed and verified)

MD5:
e6bc77c6c09379c392c85ee5e05a9c56

SHA-1:
0edfb720acefc3e7dc458473b227f382eb71e2a1

SHA-256:
0da036253b9810b2d318028a98f2077c1251c9fa2eb66ffe6903f3be53e07a6c

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
4/19/2024 6:16:43 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Linkury.B
885

Bitdefender
Adware.Linkury.B
1.0.20.1230

Emsisoft Anti-Malware
Adware.Linkury
8.14.09.03.12

G Data
Adware.Linkury
14.9.24

MicroWorld eScan
Adware.Linkury.B
15.0.0.738

Panda Antivirus
PUP/LinkUry
14.09.03.12

Reason Heuristics
PUP.Veristaff.I
14.7.28.8

Trend Micro House Call
Suspicious_GEN.F47V0613
7.2.246

VIPRE Antivirus
Adware.Linkury
30470

File size:
412.8 KB (422,696 bytes)

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\users\{user}\appdata\local\lpt\resources\ntdis_64.dll

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/8/2014 9:00:00 PM

Valid to:
7/14/2015 9:00:00 AM

Subject:
CN=Veristaff.com Inc, O=Veristaff.com Inc, L=Wilmington, S=Delaware, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0B0EA10F13BB9EB2057BECB9A30F59D4

File PE Metadata
Compilation timestamp:
7/22/2014 4:03:38 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:VMLcy63ckalaxcHOAcONFxp1WOoMXOldsQayhW:Acy63ckalaxcHOcN3WzMYsQL0

Entry address:
0x16DE0

Entry point:
4C, 89, 44, 24, 18, 89, 54, 24, 10, 48, 89, 4C, 24, 08, 48, 83, EC, 28, 83, 7C, 24, 38, 01, 75, 05, E8, D2, B6, 00, 00, 4C, 8B, 44, 24, 40, 8B, 54, 24, 38, 48, 8B, 4C, 24, 30, E8, 0F, 00, 00, 00, 48, 83, C4, 28, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 4C, 89, 44, 24, 18, 89, 54, 24, 10, 48, 89, 4C, 24, 08, 48, 83, EC, 48, C7, 44, 24, 30, 01, 00, 00, 00, 83, 7C, 24, 58, 00, 75, 10, 83, 3D, 58, BF, 04, 00, 00, 75, 07, 33, C0, E9, 1F, 01, 00, 00, 83, 7C, 24, 58, 01, 74, 07, 83, 7C, 24, 58, 02, 75, 4E, 48...
 
[+]

Code size:
281.5 KB (288,256 bytes)

The file ntdis_64.dll has been discovered within the following programs.

LPT System Updater Service  by Linkury Ltd.
This is a potentially unwanted web browser extension this is distributed and installed by PINWID LTD, ReSoft LTD., MY POP SHOP LTD and Linkury. It will display advertisements including banners and popups in the user's web browser.
81% remove it
ShowPass Smartbar  by ReSoft Ltd.
ShowPass Smartbar is an adware program (supported by various types of advertising) that is usually bundled by third party installers and download managers.
snap.do
63% remove it
 
Powered by Should I Remove It?

Remove ntdis_64.dll - Powered by Reason Core Security