Should I block it?

9%
9% of PCs block this file from running.

VersionsAdditional versions

1, 0, 0, 1 8.70%
1, 0, 0, 1 34.78%
1, 0, 0, 1 17.39%
1, 0, 0, 1 34.78%
1, 0, 0, 1 4.35%
(Note, the developer publishes each variation of this file with the same version, but the hashes are unique.)

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegSetValueExW, RegQueryValueExW, RegOpenKeyExW, RegCreateKeyExW, EqualSid, RegEnumValueW, RegDeleteValueW, SetSecurityInfo, GetSecurityDescriptorSacl, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, MakeAbsoluteSD, ConvertStringSidToSidW, GetSecurityInfo, OpenProcessToken, AddAccessAllowedAce, AdjustTokenPrivileges, InitializeAcl, LookupPrivilegeValueW, GetAce, SetKernelObjectSecurity, DuplicateTokenEx, LookupAccountNameW, OpenThreadToken, GetTokenInformation, RegCloseKey
kernel32.dll
QueueUserWorkItem, WaitForSingleObject, DeleteCriticalSection, EnterCriticalSection, InitializeCriticalSection, UnmapViewOfFile, InterlockedExchange, MapViewOfFile, CreateFileMappingW, LeaveCriticalSection, OutputDebugStringW, GetShortPathNameW, GetFileSize, CreateDirectoryW, GetTempPathW, GetWindowsDirectoryW, SetEnvironmentVariableW, GetEnvironmentStringsW, TlsGetValue, TlsFree, TlsAlloc, OpenThread, GetProcessAffinityMask, TlsSetValue, GetCurrentThreadId, GetCurrentProcessId, GetModuleHandleW, LocalFree, GetVersion, MoveFileExW, GetCurrentThread, GetComputerNameW, WideCharToMultiByte, GetEnvironmentVariableW, GetCurrentDirectoryW, VirtualFree, VirtualAlloc, CopyFileW, GetFileAttributesW, FindClose, FindFirstFileW, InterlockedCompareExchange, GetProcAddress, GetTickCount, GetModuleFileNameW, FreeLibrary, WaitNamedPipeW, Sleep, CreateFileW, SetLastError, GetLastError, CloseHandle, ReadFile, WriteFile, MultiByteToWideChar, QueryPerformanceFrequency, SetEvent, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetSystemTimeAsFileTime, GetFileSizeEx, SetFilePointerEx, GetSystemTime, CompareFileTime, QueryPerformanceCounter, QueueUserAPC, HeapFree, ExitThread, CreateMutexW, GetLocalTime, SetThreadPriority, DuplicateHandle, SetEndOfFile, ReleaseMutex, WaitForSingleObjectEx, HeapAlloc, HeapDestroy, HeapCreate, LoadLibraryExW, LoadLibraryW, GetCommandLineW, GetCurrentProcess, SystemTimeToFileTime, DeleteFileW
msvcp80.dll
DllMain
msvcr80.dll
DllMain
ntdll.dll
ZwFlushBuffersFile, ZwCreateKey, ZwWriteFile, ZwReadFile, ZwReleaseMutant, ZwQueryInformationFile, ZwQueryValueKey, RtlInitUnicodeString, ZwSetInformationFile, ZwOpenKey, ZwCreateFile, ZwWaitForMultipleObjects, RtlFreeUnicodeString, ZwResetEvent, ZwQueryKey, ZwDelayExecution, ZwOpenThread, ZwYieldExecution, ZwClose, ZwCreateEvent, ZwCreateMutant, ZwQueryInformationThread, ZwQueryInformationProcess, ZwOpenMutant, ZwSetEvent, RtlGetVersion, ZwOpenEvent, ZwSetValueKey, RtlFormatCurrentUserKeyPath, ZwOpenFile, ZwQueryFullAttributesFile, ZwWaitForSingleObject, _fltused, _allmul, memcpy, memset, _chkstk, _snwprintf
ole32.dll
CoInitialize, CoUninitialize
shell32.dll
SHGetSpecialFolderPathW
user32.dll
GetForegroundWindow, CharUpperBuffW, CharUpperBuffA, CharLowerBuffA, MessageBoxW, RegisterWindowMessageW, CharLowerBuffW, wsprintfW, PeekMessageW, TranslateMessage, DispatchMessageW, MsgWaitForMultipleObjects
Export table
_IswLog_FlushThread@4
NP_GetEntryPoints
NP_GetMIMEDescription
NP_Initialize
NP_Shutdown

npffapi.dll

npFFApi

Remove npffapi.dll
Version:   1, 0, 0, 1
MD5:   7f46a97e20996ab910fe980ccd56d8ff
SHA1:   ea9c8265d4d07d480043d725bf4e57bdafc1fb21
SHA256:   0ccbc4120eee84adf00f72c268968aef28c29abaea809e1cb7d766426b07e26e

Overview

npffapi.dll is loaded as dynamic link library that runs in the context of the Google Chrome web browser.

DetailsDetails

File name:npffapi.dll
Product name:npFFApi
Typical file path:C:\Program Files\checkpoint\zaforcefield\trustchecker\bin\npffapi.dll
Original name:npFFApi
File version:1, 0, 0, 1
Size:220 KB (225,280 bytes)
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

BehaviorsBehaviors

Mozilla plugins
  • @checkpoint.com/FFApi
Google Chrome plugins
Stored per user in the directory 'Google\Chrome\User Data\Default\Preferences'
  • Name: 'npFFApi.dll'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 52.17%
Microsoft Windows XP 17.39%
Windows 7 Ultimate 8.70%
Windows Vista Home Basic 4.35%
Windows 8 Pro 4.35%
Windows 7 Ultimate N 4.35%
Windows Vista Ultimate 4.35%
Windows 7 Professional 4.35%

Distribution by countryDistribution by country

United States installs about 60.87% of npFFApi.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 66.67%
Acer 33.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE