Is unlockfps_nc.dll safe?
Only 2 of 75 engines flagged this unsigned FPS utility, but a tier-1 PUA label and conflicting sandbox results warrant caution.
Most antivirus engines did not flag the file, and its long-standing, broad circulation lowers the likelihood of conventional malware. However, ESET-NOD32 identifies a potentially unwanted application, the executable is unsigned, and one runtime result was unfavorable, so it should only be used after verifying its official source.
ab383e989a6ea0ea58…c907716a990c10Recommended next actions
Before using
Do not use it until the source and publisher can be verified independently.
If you already used it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Reinstall the parent software from the developer's official site instead of replacing this component by itself.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Most antivirus engines did not flag the file, and its long-standing, broad circulation lowers the likelihood of conventional malware. However, ESET-NOD32 identifies a potentially unwanted application, the executable is unsigned, and one runtime result was unfavorable, so it should only be used after verifying its official source.
Two of 75 engines raised detections, including one tier-1 PUA label, but there is no strong family consensus. Runtime analysis produced conflicting outcomes and found no offensive-only techniques, so the unfavorable sandbox result is not independently conclusive. The sample has been submitted by 2,641 sources over an established period, and researcher feeds supplied no corroborating malware match. Its unsigned status prevents publisher verification, while the one prior safe imphash match is too weak because it lacks a signer co-match. Taken together, the evidence fits an unwanted or modified utility more closely than a clearly identified malware family, but it does not justify unrestricted trust.
What We Detected
Two of 75 antivirus engines flagged the file. ESET-NOD32 described it as a Generik.IFEJXIS potentially unwanted application, while Cylance returned the generic label “Unsafe”; there is no strong tier-1 family consensus. The executable is unsigned, so its publisher and distribution provenance cannot be authenticated.
Threat Behavior
One recorded sandbox outcome was unfavorable and another was clean. The observed MITRE techniques were all categorized as ambient, with behaviour.offensiveCount=0, no persistence indicators, and no malicious dropped child. Eight contacted hosts were checked without a malicious or suspicious cache hit, but that check did not cover every distinct observed contact, so no complete host-reputation conclusion is available.
What To Do Now
Obtain the file only from the utility's official release channel and verify its hash against the publisher's release information. Keep endpoint protection enabled, and avoid running it if its source cannot be verified or if it requests unexpected privileges or system changes.
Where this verdict could be wrong4 caveats
- ESET-NOD32 is a tier-1 engine and labels the sample as a potentially unwanted application, so the detection cannot be dismissed as low-trust noise.
- behaviour.hasMaliciousSandboxVerdict=true is a meaningful counter-signal, although the recorded sandbox outcomes conflict and no offensive-only MITRE techniques were observed.
- The file is unsigned despite signing.applicable=true, so its publisher and release provenance cannot be authenticated.
- The sole similarHashes safe result is matchKind=imphash with signerMatchesSubject=false, making an installer or build-framework collision possible.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Only 2/75 engines produced malicious detections.
- Sixteen of 17 reporting tier-1 engines did not flag the sample.
- The sample has 2,641 submitting sources and 3,376 submissions over an established period.
- behaviour.offensiveCount=0 and droppedChildren.hasMaliciousChild=false.
- YARAify, CIRCL, and MalwareBazaar supplied no corroborating hit.
- ESET-NOD32 supplied a tier-1 potentially unwanted application label.
- behaviour.hasMaliciousSandboxVerdict=true, although the recorded outcomes conflict.
- The executable is unsigned and has no established signer history.
- The contacted-host reputation check did not cover every observed contact.
- The filename suggests a system-modifying FPS utility, while publisher provenance is unavailable.
Use only a hash-verified copy from the utility's official release channel and keep endpoint protection enabled. If provenance cannot be confirmed, quarantine or remove the file rather than executing it.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete2 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial8 of 28 contacted hosts were cross-checked; coverage is incomplete.
YARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 10MITRE ATT&CK techniques
- 4spawned processes
- 29network contacts
- 27filesystem & mutex artifacts
What this file does
Observed actions and their security significance
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Scans through your files and folders.
Moderate concern: Checked the environment for virtualisation or analysis tools.
Note: Collects details about your system.
Note: Loads extra code modules while running.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
unlockfps_nc.dll
ab383e989a6ea0ea58024889be36e622fc2dc75b0a3f84230dc907716a990c10
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\Desktop\unlockfps_nc.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Users\user\Desktop\unlockfps_nc.exe"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Microsoft Compatibility Appraiser
C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
04Isolated runtime analysis - Written fileObserved
BaseNamedObjects
\Sessions\1\BaseNamedObjects
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
ys.ex-m.net
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostDerived
aka.ms
Saved reputation verdict: safe.
07Contacted-host cross-check - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox; 1 returned "malicious".
Adversary techniques mapped to the MITRE ATT&CK framework.
- ys.ex-m.net
- aka.ms
- assets.msn.com
- assets.msn.com-ion.edgesuite.net
- a1666.dscr.akamai.net
- redirector.gvt1.com
- 104.21.45.208
- 13.89.178.26
- 74.178.76.128
- 2.16.233.117
- 23.47.72.69
- 199.232.210.172
- 135.233.95.144
- 23.209.94.84
- 20.50.73.4
- 104.124.13.226
- https://ys.ex-m.net/fps-unlock/version
- http://clients2.google.com/time/1/current?cup2key=8:WuXN3YNmuxYT2zFH65cAxA72CShcE251JKYw6XxXGNo&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
- http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3/a6ADK8NraY2GXzVaYrHG4AQUb6t+2v+XQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY=
- HKEY_USERS\S-1-5-21-4270068108-2931534202-3907561125-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids\exefile
- C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
- \Sessions\1\BaseNamedObjects
- C:\Users\user\AppData\Local\Microsoft\Windows\History
- C:\Users\user\AppData\Local\Microsoft\Windows\INetCache
- C:\Users\user\AppData\Local\Microsoft\Windows\INetCookies
- C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics
- C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-69410744-C0.pma
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\the-real-index~RF5c8f5.TMP
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.89.1_0
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.89.1_0\128.png
- 286B345F-A2EB-4FF3-83E9-2DD83B87694A
- Local\!BrowserEmulation!SharedMemory!Mutex
- Local\ZonesCacheCounterMutex
- Local\ZonesLockedCacheCounterMutex
- IsoScope_1200_IE_EarlyTabStart_0x1380_Mutex
Files this sample writes at runtime
This file drops 1 child at runtime. None are currently flagged malicious in our cache.
- 0300e9ddb527990e8b59…95e82dNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 2 / 75engines flagged
- 2,641sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 isolated runtime environment classified the observed behavior as malicious.
Verdict inputView chapterProvenanceObservedSourceIsolated runtime analysisObserved at - 02
2 of 75 antivirus engines flagged the file, including Cylance and ESET-NOD32.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has a long, established submission history across 2,641 sources.
ProvenanceDerivedSourceSubmission historyObserved at - 04
Scanned file: unlockfps_nc.dll — ab383e989a6ea0ea58024889be36e622fc2dc75b0a3f84230dc907716a990c10
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\unlockfps_nc.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Users\user\Desktop\unlockfps_nc.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Microsoft Compatibility Appraiser — C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: BaseNamedObjects — \Sessions\1\BaseNamedObjects
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: ys.ex-m.net — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: aka.ms — Saved reputation verdict: safe.
ProvenanceDerivedSourceContacted-host cross-checkObserved at
Detection sources at a glance
Category: pua
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
2 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- unlockfps_nc.dll
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 3.4 MB
- Last analyzed
- Oct 1, 2026, 4:09 PM UTC
ab383e989a6ea0ea58024889be36e622fc2dc75b0a3f84230dc907716a990c10Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't use it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
Do not delete or replace the component manually. Quarantine it with your antivirus or repair the parent software from its official source. Reinstall the parent software from the developer's official site instead of replacing this component by itself.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is unlockfps_nc.dll safe, or is it malware?
What is unlockfps_nc.dll?
How many antivirus engines detected unlockfps_nc.dll?
I already downloaded and used unlockfps_nc.dll — what should I do?
How do I remove unlockfps_nc.dll?
What kind of malware is unlockfps_nc.dll?
What is the SHA-256 hash of unlockfps_nc.dll?
How up to date is this analysis of unlockfps_nc.dll?
Community
Member reviews and reports for this exact file hash.