local32spl.dll

The module local32spl.dll has been detected as a potentially unwanted program by 13 anti-malware scanners.
MD5:
5b72aa7d3218f583faf64ab9865eb521

SHA-1:
2e4a8033888c622c257658c547cd61f4a5ccae9d

SHA-256:
a1d4fe20c0e87fde0e2fa5503477b7a79b76382cbbe3ee9bd3358881dafa6525

Scanner detections:
13 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 4:48:34 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.326359
-40

AhnLab V3 Security
PUP/Win32.ELEX.R196160
3.8.3.16

Arcabit
Trojan.Graftor.D4FAD7
1.0.0.802

Baidu Antivirus
Win32.Trojan.WisdomEyes.16070401.9500
4.0.3.17316

Bitdefender
Gen:Variant.Graftor.326359
1.0.20.375

Emsisoft Anti-Malware
Gen:Variant.Graftor.326359
8.17.03.16.08

ESET NOD32
Win32/Adware.ELEX.GF (variant)
11.15096

F-Secure
Gen:Variant.Graftor.326359
11.2017-16-03_5

G Data
Gen:Variant.Graftor.326359
17.3.A:25.11207B:25.9095

IKARUS anti.virus
PUA.Elex
0.2.1.2

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.-1317

MicroWorld eScan
Gen:Variant.Graftor.326359
18.0.0.225

Qihoo 360 Security
HEUR/QVM30.1.0000.Malware.Gen
1.0.0.1120

File size:
267.5 KB (273,920 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\narech client\local32spl.dll

File PE Metadata
Compilation timestamp:
3/8/2017 1:40:06 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x16B3

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 76, 6E, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 73, EA, 01, 00, 83, C4, 0C, 5D, C2, 0C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 56, 8B, F1, 83, 7E, 14, 08, 72, 0A, FF, 36, E8, 08, 86, 00, 00, 83, C4, 04, C7, 46, 14, 07, 00, 00, 00, 33, C0, C7, 46, 10, 00, 00, 00, 00, 66, 89, 06, 5E, C3, 55, 8B, EC, 8B, 45, 08, 66, 8B, 08, 83, C0, 02, 66, 85, C9, 75, F5, 2B, 45, 08, D1, F8, 48, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
201 KB (205,824 bytes)

Remove local32spl.dll - Powered by Reason Core Security