Should I block it?

90%
90% of PCs block this file from running.
Possible reason:
Multiple malware detections

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
LookupPrivilegeValueA, AdjustTokenPrivileges, OpenProcessToken, RegCreateKeyA, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, SetFileSecurityA, SetSecurityDescriptorOwner, AllocateAndInitializeSid, RegOpenKeyA, RegQueryValueExA, RegSetValueExA, RegCloseKey, GetUserNameA
gdi32.dll
SetViewportOrgEx, OffsetViewportOrgEx, SetViewportExtEx, ScaleViewportExtEx, SetWindowExtEx, ScaleWindowExtEx, SetMapMode, PtVisible, RectVisible, TextOutA, ExtTextOutA, Escape, GetStockObject, SelectObject, RestoreDC, SaveDC, DeleteDC, DeleteObject, GetDeviceCaps, GetObjectA, SetBkColor, SetTextColor, GetClipBox, CreateBitmap
kernel32.dll
HeapFree, HeapAlloc, ExitProcess, TerminateProcess, GetTimeZoneInformation, GetCommandLineA, RtlUnwind, RaiseException, HeapSize, HeapReAlloc, GetACP, HeapDestroy, HeapCreate, VirtualAlloc, IsBadWritePtr, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, FreeEnvironmentStringsW, GetEnvironmentStrings, GetEnvironmentStringsW, SetUnhandledExceptionFilter, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW, SetStdHandle, IsBadReadPtr, IsBadCodePtr, CompareStringA, CompareStringW, SetEnvironmentVariableA, SetEndOfFile, FlushFileBuffers, SetFilePointer, WriteFile, ReadFile, GetCurrentProcess, InterlockedIncrement, GetOEMCP, GetCPInfo, GlobalFlags, lstrcmpA, GetProcessVersion, SetLastError, FreeLibrary, GlobalGetAtomNameA, lstrcmpiA, GlobalAddAtomA, GlobalFindAtomA, GlobalDeleteAtom, GetVersion, lstrlenA, lstrcpynA, GetModuleFileNameA, lstrcpyA, GetCurrentProcessId, lstrcatA, InterlockedDecrement, TlsGetValue, LocalReAlloc, TlsSetValue, EnterCriticalSection, GlobalAlloc, GlobalReAlloc, GlobalLock, LeaveCriticalSection, TlsFree, GlobalHandle, GlobalUnlock, GlobalFree, DeleteCriticalSection, TlsAlloc, InitializeCriticalSection, LocalAlloc, GetCurrentThreadId, CreateFileA, LocalFree, OpenProcess, CloseHandle, GetSystemTime, GetLocalTime, MultiByteToWideChar, WideCharToMultiByte, GetModuleHandleA, GetProcAddress, LoadLibraryA, GetLastError, GetVersionExA, GetSystemDirectoryA, CreateDirectoryA, VirtualFree
msvcrt21.dll
DllMain
psapi.dll
GetModuleFileNameExA
user32.dll
LoadIconA, SetWindowTextA, IsWindowEnabled, LoadCursorA, GetSysColorBrush, ReleaseDC, GetDC, GetClassNameA, PtInRect, ClientToScreen, LoadStringA, PostQuitMessage, DestroyMenu, TabbedTextOutA, DrawTextA, GrayStringA, SetFocus, AdjustWindowRectEx, GetClientRect, CopyRect, PostMessageA, GetTopWindow, MessageBoxA, GetCapture, WinHelpA, GetClassInfoA, RegisterClassA, GetMenu, GetMenuItemCount, GetSubMenu, GetMenuItemID, GetDlgItem, GetWindowTextA, GetDlgCtrlID, DefWindowProcA, DestroyWindow, CreateWindowExA, GetClassLongA, SetPropA, GetPropA, CallWindowProcA, RemovePropA, GetMessagePos, GetLastActivePopup, GetForegroundWindow, SetForegroundWindow, GetWindow, GetWindowLongA, SetWindowLongA, SetWindowPos, RegisterWindowMessageA, SystemParametersInfoA, IsIconic, GetWindowPlacement, GetWindowRect, GetSystemMetrics, GetMenuCheckMarkDimensions, LoadBitmapA, GetMenuState, ModifyMenuA, SetMenuItemBitmaps, MapWindowPoints, EnableWindow, GetSysColor, SetWindowsHookExA, CheckMenuItem, EnableMenuItem, GetFocus, GetParent, GetNextDlgTabItem, UnhookWindowsHookEx, DispatchMessageA, SendMessageA, GetKeyState, CallNextHookEx, PeekMessageA, GetMessageTime
winspool.drv
OpenPrinterA, DocumentPropertiesA, ClosePrinter

ntshriu.dll

WebSecure by Biz Secure Labs Pvt. Ltd

Remove ntshriu.dll
Version:   1, 0, 0, 1
MD5:   7f09afbf71da8276015d2f87fbcae69d
SHA1:   7599a7d820185d5463e67bd6b213c256eb8ce968
SHA256:   1cf943941b4fb38783578dea524c95a93a2094a5a045334dafe9b22ee676f2ef
Warning 4 antivirus scanners has detected malware.

Overview

ntshriu.dll is malware that is loaded as dynamic link library that runs in the context of a process. This particular version is usually found on Windows 7 Ultimate (6.1.7601.65536).

DetailsDetails

File name:ntshriu.dll
Publisher:Biz Secure Labs Pvt. Ltd.
Product name:WebSecure
Description:ntshriu
Typical file path:C:\Windows\System32\ntshriu.dll
File version:1, 0, 0, 1
Size:116 KB (118,784 bytes)
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

MalwareMalware detections

Based on 40+ industry antivirus scanners, 4 of them detected the following malware.
Antivirus engineEngine versionDetection
avast! 6.0.1289.0 Win32:Dropper-gen [Drp]
G Data 13.9.22 Win32:Dropper-gen
Ikarus T3.1.4.3.0 Virus.Win32.Dropper
Symantec 20131.1.0.101 WS.Reputation.1

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 100.00%

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE