Home Possibly Unwanted Program Navegaki

Navegaki

Posted: August 27, 2015

Threat Metric

Ranking: 4,858
Threat Level: 1/10
Infected PCs: 85,093
First Seen: August 27, 2015
Last Seen: October 17, 2023
OS(es) Affected: Windows


Navegaki is a Potentially Unwanted Program (PUP) that may be installed without the user's knowledge. The good news is that despite its deceptive marketing tricks, Navegaki isn't threatening, and its installation doesn't pose a threat to your privacy or the data you store on your computer. However, Navegaki may change the way your Web browser works by changing your default homepage and search service provider to Navegaki.com immediately, a low-quality search engine that may host links to unpopular and slightly suspicious websites. The Navegaki.com homepage features a search engine that you should not use if you want to be provided with reliable and legitimate search results. The Navegaki.com search features may provide you with results that contain sponsored content and advertisements that may prevent you from viewing the most relevant results. While this PUP isn't threatening, its presence on your computer may not bring you any positive things, and there isn't a single reason to keep Navegaki installed. If you find this program on your computer or if you suddenly see Navegaki.com in your Web browser, then you should use a trustworthy anti-malware utility to scan and clean your utility. Anti-virus vendors identify Navegaki as a Potentially Unwanted Program, and reputable anti-malware scanners can identify and remove all of Navegaki's files, registry entries, and other components successfully.

Aliases

Generic6.KSM [AVG]Riskware/Navegaki [Fortinet]Trj/CI.A [Panda]Artemis [McAfee-GW-Edition]ApplicUnwnt [Comodo]not-a-virus:AdWare.Win32.Amonetize.aafo [Kaspersky]Adware ( 004b48a71 ) [K7AntiVirus]Artemis!2F44459746DF [McAfee]AdWare.Amonetize.r5 (Not a Virus) [CAT-QuickHeal]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



c:\windows\syswow64\ntserver\service.exe File name: service.exe
Size: 91.23 KB (91232 bytes)
MD5: 3664aa00e145327d068eff77131d9a75
Detection count: 33,197
File type: Executable File
Mime Type: unknown/exe
Path: c:\windows\syswow64\ntserver\service.exe
Group: Malware file
Last Updated: February 19, 2023
%WINDIR%\System32\NTServer\ntsvc.exe File name: ntsvc.exe
Size: 326.54 KB (326544 bytes)
MD5: a0821a18c170a55699518fbbc6a88c57
Detection count: 13,390
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\System32\NTServer\ntsvc.exe
Group: Malware file
Last Updated: February 19, 2023
%APPDATA%\gameboxsetup.exe File name: gameboxsetup.exe
Size: 26.32 MB (26325872 bytes)
MD5: 3d4259bfde5e834f4acc5889be8f7097
Detection count: 5,045
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: August 2, 2022
%APPDATA%\ntsvc\ntsvc.exe File name: ntsvc.exe
Size: 403.32 KB (403320 bytes)
MD5: d1b91842024ef557819f5835a297c709
Detection count: 464
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\ntsvc
Group: Malware file
Last Updated: March 22, 2016

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%AppData%\NetService\conf.ini%AppData%\NetService\sc.exeHKEY..\..\..\..{RegistryKeys}SOFTWARE\NtSvcHandlerSOFTWARE\Wow6432Node\NtSvcHandlerSYSTEM\ControlSet001\services\SedSYSTEM\ControlSet002\services\SedSYSTEM\CurrentControlSet\services\Sed

Additional Information

The following directories were created:
%APPDATA%\Mactowebise%APPDATA%\Macwebtoise%APPDATA%\NetworkService%PROGRAMFILES%\navegaki

Related Posts

Loading...