Should I block it?

9%
9% of PCs block this file from running.

VersionsAdditional versions

1, 0, 0, 1 8.70%
1, 0, 0, 1 34.78%
1, 0, 0, 1 17.39%
1, 0, 0, 1 34.78%
1, 0, 0, 1 4.35%
(Note, the developer publishes each variation of this file with the same version, but the hashes are unique.)

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegSetValueExW, RegQueryValueExW, RegOpenKeyExW, RegCreateKeyExW, EqualSid, RegEnumValueW, RegDeleteValueW, SetSecurityInfo, GetSecurityDescriptorSacl, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, MakeAbsoluteSD, ConvertStringSidToSidW, GetSecurityInfo, OpenProcessToken, AddAccessAllowedAce, AdjustTokenPrivileges, InitializeAcl, LookupPrivilegeValueW, GetAce, SetKernelObjectSecurity, DuplicateTokenEx, LookupAccountNameW, OpenThreadToken, GetTokenInformation, RegCloseKey
kernel32.dll
QueueUserWorkItem, WaitForSingleObject, DeleteCriticalSection, EnterCriticalSection, InitializeCriticalSection, UnmapViewOfFile, InterlockedExchange, MapViewOfFile, CreateFileMappingW, LeaveCriticalSection, OutputDebugStringW, GetShortPathNameW, GetFileSize, CreateDirectoryW, GetTempPathW, GetWindowsDirectoryW, SetEnvironmentVariableW, GetEnvironmentStringsW, TlsGetValue, TlsFree, TlsAlloc, OpenThread, GetProcessAffinityMask, TlsSetValue, GetCurrentThreadId, GetCurrentProcessId, GetModuleHandleW, LocalFree, GetVersion, MoveFileExW, GetCurrentThread, GetComputerNameW, WideCharToMultiByte, GetEnvironmentVariableW, GetCurrentDirectoryW, VirtualFree, VirtualAlloc, CopyFileW, GetFileAttributesW, FindClose, FindFirstFileW, InterlockedCompareExchange, GetProcAddress, GetTickCount, GetModuleFileNameW, FreeLibrary, WaitNamedPipeW, Sleep, CreateFileW, SetLastError, GetLastError, CloseHandle, ReadFile, WriteFile, MultiByteToWideChar, QueryPerformanceFrequency, SetEvent, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetSystemTimeAsFileTime, GetFileSizeEx, SetFilePointerEx, GetSystemTime, CompareFileTime, QueryPerformanceCounter, QueueUserAPC, HeapFree, ExitThread, CreateMutexW, GetLocalTime, SetThreadPriority, DuplicateHandle, SetEndOfFile, ReleaseMutex, WaitForSingleObjectEx, HeapAlloc, HeapDestroy, HeapCreate, LoadLibraryExW, LoadLibraryW, GetCommandLineW, GetCurrentProcess, SystemTimeToFileTime, DeleteFileW
msvcp80.dll
DllMain
msvcr80.dll
DllMain
ntdll.dll
ZwFlushBuffersFile, ZwCreateKey, ZwWriteFile, ZwReadFile, ZwReleaseMutant, ZwQueryInformationFile, ZwQueryValueKey, RtlInitUnicodeString, ZwSetInformationFile, ZwOpenKey, ZwCreateFile, ZwWaitForMultipleObjects, RtlFreeUnicodeString, ZwResetEvent, ZwQueryKey, ZwDelayExecution, ZwOpenThread, ZwYieldExecution, ZwClose, ZwCreateEvent, ZwCreateMutant, ZwQueryInformationThread, ZwQueryInformationProcess, ZwOpenMutant, ZwSetEvent, RtlGetVersion, ZwOpenEvent, ZwSetValueKey, RtlFormatCurrentUserKeyPath, ZwOpenFile, ZwQueryFullAttributesFile, ZwWaitForSingleObject, _fltused, _allmul, memcpy, memset, _chkstk, _snwprintf
ole32.dll
CoInitialize, CoUninitialize
shell32.dll
SHGetSpecialFolderPathW
user32.dll
GetForegroundWindow, CharUpperBuffW, CharUpperBuffA, CharLowerBuffA, MessageBoxW, RegisterWindowMessageW, CharLowerBuffW, wsprintfW, PeekMessageW, TranslateMessage, DispatchMessageW, MsgWaitForMultipleObjects
Export table
_IswLog_FlushThread@4
NP_GetEntryPoints
NP_GetMIMEDescription
NP_Initialize
NP_Shutdown

npffapi.dll

npFFApi

Remove npffapi.dll
Version:   1, 0, 0, 1
MD5:   787fbcb838b5a7ba4f7db3cf089c9cf6
SHA1:   d7938188b3f1e0b1309da610f87dba6b1cc3e3da
SHA256:   8da524367d9e76c4b9193669c623bf40377adfe6e817e9f97b12e82d2428989f

Overview

npffapi.dll is loaded as dynamic link library that runs in the context of the Google Chrome web browser.

DetailsDetails

File name:npffapi.dll
Product name:npFFApi
Typical file path:C:\Program Files\checkpoint\zaforcefield\trustchecker\bin\npffapi.dll
Original name:npFFApi
File version:1, 0, 0, 1
Size:220 KB (225,280 bytes)
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

BehaviorsBehaviors

Mozilla plugins
  • @checkpoint.com/FFApi
Google Chrome plugins
Stored per user in the directory 'Google\Chrome\User Data\Default\Preferences'
  • Name: 'npFFApi.dll'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 52.17%
Microsoft Windows XP 17.39%
Windows 7 Ultimate 8.70%
Windows Vista Home Basic 4.35%
Windows 8 Pro 4.35%
Windows 7 Ultimate N 4.35%
Windows Vista Ultimate 4.35%
Windows 7 Professional 4.35%

Distribution by countryDistribution by country

United States installs about 60.87% of npFFApi.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 66.67%
Acer 33.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE