Dmitry Sokolov recommends UnHackMe!
UnHackMe is a powerful tool against malware.UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!
Malware Analysis of Adware.Downware.14130 – NP_TEST_NETSCAPE_PLUGIN.DLL
Created files:
%LOCAL APPDATA%\ORBITUM\APPLICATION\48.0.2564.91\PLUGINS\LIBVLCCORE.DLL
%LOCAL APPDATA%\ORBITUM\APPLICATION\48.0.2564.91\PLUGINS\NPVLC.DLL
%LOCAL APPDATA%\ORBITUM\APPLICATION\48.0.2564.91\PLUGINS\NP_TEST_NETSCAPE_PLUGIN.DLL
%LOCAL APPDATA%\ORBITUM\APPLICATION\48.0.2564.91\PLUGINS\PLUGINS\ACCESS\LIBACCESS_BD_PLUGIN.DLL
%LOCAL APPDATA%\ORBITUM\APPLICATION\48.0.2564.91\PLUGINS\PLUGINS\ACCESS\LIBACCESS_MMS_PLUGIN.DLL
Autostart registry keys:
HKLM\SOFTWARE\CLASSES\ORBITUMHTM.5H2QR4GU3NYWVL3TJ6VO2JWGTI\SHELL\OPEN\COMMAND\: “”%LOCAL APPDATA%\ORBITUM\APPLICATION\ORBITUM.EXE” — “%1″”
HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\ORBITUM.5H2QR4GU3NYWVL3TJ6VO2JWGTI\SHELL\OPEN\COMMAND\: “”%LOCAL APPDATA%\ORBITUM\APPLICATION\ORBITUM.EXE””
HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Orbitum\DisplayName: “Orbitum”
HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ORBITUM\UNINSTALLSTRING: “”%LOCAL APPDATA%\ORBITUM\APPLICATION\48.0.2564.91\INSTALLER\SETUP.EXE” –UNINSTALL”
HKCU\SOFTWARE\ORBITUM\UPDATE\CLIENTSTATE\{8A69D345-D564-463C-AFF1-A69D9E530F96}\UNINSTALLSTRING: “%LOCAL APPDATA%\ORBITUM\APPLICATION\48.0.2564.91\INSTALLER\SETUP.EXE”
Detected by UnHackMe:
NP_TEST_NETSCAPE_PLUGIN.DLL
DEFAULT LOCATION: %LOCAL APPDATA%\ORBITUM\APPLICATION\48.0.2564.91\PLUGINS\NP_TEST_NETSCAPE_PLUGIN.DLL
Dropper hash(md5): 5ae0295776433cfcb5f3c95ab0c89754
UnHackMe
removes malware invisible for your antivirus!
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.