What is ns?
The Malwarebytes research team has determined that ns is adware. These adware applications display advertisements not originating from the sites you are browsing.
How do I know if my computer is affected by ns?
You may see this entry in your list of installed programs:

How did ns get on my computer?
Adware applications use different methods for distributing themselves. This particular one was bundled with other software.
How do I remove ns?
Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted program.
- Please download Malwarebytes Anti-Malware to your desktop.
- Double-click mbam-setup-{version}.exe and follow the prompts to install the program.
- At the end, be sure a check-mark is placed next to:
Launch Malwarebytes Anti-Malware - Then click Finish.
- Once the program has loaded, select Scan Now. Or select the Threat Scan from the Scan menu.
- If an update is available, it will be implemented before the rest of the scanning procedure.
- When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
- Restart your computer when prompted to do so.
- No, Malwarebytes' Anti-Malware removes ns completely.
We hope our application and this guide have helped you eradicate this hijacker.
As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the ns adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late.
Technical details for experts
Possible signs in FRST logs:
() C:\Program Files (x86)\ns\ns.exe R2 ns; C:\Program Files (x86)\ns\ns.exe [4448256 2016-08-25] () [File not signed] <==== ATTENTION C:\Program Files (x86)\ns ns (HKLM-x32\...\ns) (Version: 0.0.125 - ns) C:\Program Files (x86)\ns\boost_thread-vc120-mt-1_59.dll () C:\Program Files (x86)\ns\boost_system-vc120-mt-1_59.dll () C:\Program Files (x86)\ns\boost_chrono-vc120-mt-1_59.dll () C:\Program Files (x86)\ns\boost_date_time-vc120-mt-1_59.dll () C:\Program Files (x86)\ns\boost_filesystem-vc120-mt-1_59.dll () C:\Program Files (x86)\ns\boost_iostreams-vc120-mt-1_59.dll () C:\Program Files (x86)\ns\boost_bzip2-vc120-mt-1_59.dll () C:\Program Files (x86)\ns\lua53.dll () C:\Program Files (x86)\ns\zlib.dll () C:\Program Files (x86)\ns\libesedb.dllAlterations made by the installer:
File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\ns Adds the file boost_bzip2-vc120-mt-1_59.dll"="10/20/2015 2:43 PM, 54784 bytes, A Adds the file boost_chrono-vc120-mt-1_59.dll"="10/20/2015 2:43 PM, 25600 bytes, A Adds the file boost_date_time-vc120-mt-1_59.dll"="10/20/2015 2:43 PM, 40960 bytes, A Adds the file boost_filesystem-vc120-mt-1_59.dll"="10/20/2015 2:43 PM, 103424 bytes, A Adds the file boost_iostreams-vc120-mt-1_59.dll"="10/20/2015 2:43 PM, 52224 bytes, A Adds the file boost_system-vc120-mt-1_59.dll"="10/20/2015 2:43 PM, 16896 bytes, A Adds the file boost_thread-vc120-mt-1_59.dll"="10/20/2015 2:44 PM, 82944 bytes, A Adds the file cpprest120_xp_2_6.dll"="10/21/2015 10:36 AM, 2364928 bytes, A Adds the file EULA.txt"="8/25/2016 9:57 AM, 10712 bytes, A Adds the file libeay32.dll"="10/20/2015 3:00 PM, 1175040 bytes, A Adds the file libesedb.dll"="8/25/2016 9:57 AM, 780800 bytes, A Adds the file lua53.dll"="12/14/2015 7:28 PM, 206336 bytes, A Adds the file msvcp120.dll"="10/5/2013 12:38 PM, 455328 bytes, A Adds the file msvcr120.dll"="10/5/2013 12:38 PM, 970912 bytes, A Adds the file ns.exe"="8/25/2016 10:20 AM, 4448256 bytes, A Adds the file ssleay32.dll"="10/20/2015 3:00 PM, 274432 bytes, A Adds the file Uninstaller.exe"="9/7/2016 8:58 AM, 57621 bytes, A Adds the file zlib.dll"="10/21/2015 8:52 AM, 68096 bytes, A Adds the folder C:\Users\{username}\AppData\Local\nsData\windows_titles Adds the file win_titles.db"="9/7/2016 8:58 AM, 2048 bytes, A Adds the folder C:\Users\{username}\AppData\Local\nsData\windows_titles\temp Adds the file 0.csv.bz2.cr"="9/7/2016 9:00 AM, 507 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData Adds the file settings.db"="9/7/2016 8:58 AM, 3072 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\apps Adds the file db_0.db"="9/7/2016 8:59 AM, 9216 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\apps\temp Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\browser_downloads Adds the file db_0.db"="9/7/2016 8:59 AM, 3072 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\browser_downloads\temp Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\browser_history Adds the file history.db"="9/7/2016 8:59 AM, 3072 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\browser_history\temp Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\browsers_info Adds the file db_0.db"="9/7/2016 8:59 AM, 3072 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\browsers_info\temp Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\browsers_manager Adds the file e507fc26_1473231531.dat"="9/7/2016 8:59 AM, 21037056 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\chrome_cdb_manager Adds the file 21a444c6_1473231548.dat"="9/5/2016 12:39 PM, 17408 bytes, A Adds the file cfab9f26_1473231548.dat"="8/24/2016 8:08 AM, 28672 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\data\1473231516 Adds the file apps.3.0.72b6c25d.csv.bz2.cr"="9/7/2016 8:59 AM, 940 bytes, A Adds the file browser_downloads.1.0.be605719.csv.bz2.cr"="9/7/2016 8:59 AM, 733 bytes, A Adds the file browser_history.2.0.8ea2ccc8.csv.bz2.cr"="9/7/2016 8:59 AM, 1262 bytes, A Adds the file browser_history.2.1.ae049236.csv.bz2.cr"="9/7/2016 8:59 AM, 733 bytes, A Adds the file browser_history.2.2.16a63199.csv.bz2.cr"="9/7/2016 8:59 AM, 1180 bytes, A Adds the file browser_history.2.3.42dd019b.csv.bz2.cr"="9/7/2016 8:59 AM, 1069 bytes, A Adds the file browsers_info.1.0.b20dd2b3.csv.bz2.cr"="9/7/2016 8:59 AM, 474 bytes, A Adds the file geo.1.0.e1dfb0a8.csv.bz2.cr"="9/7/2016 8:59 AM, 511 bytes, A Adds the file os_info.1.0.939660f1.csv.bz2.cr"="9/7/2016 8:59 AM, 598 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\fandango Adds the file db_0.db"="9/7/2016 8:58 AM, 15360 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\fandango\temp Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\fb_info Adds the file db_2.db"="9/7/2016 8:58 AM, 10240 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\fb_info\temp Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\geo Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\geo\temp Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\google Adds the file db_0.db"="9/7/2016 8:58 AM, 7168 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\google\temp Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\live Adds the file db_0.db"="9/7/2016 8:58 AM, 7168 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\live\temp Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\logs Adds the file 1473231516.log"="9/7/2016 8:58 AM, 0 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\netflix Adds the file db_0.db"="9/7/2016 8:58 AM, 18432 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\netflix\temp Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\opened_processes Adds the file data.db"="9/7/2016 8:58 AM, 9216 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\opera_cdb_manager Adds the file cfab9f26_1473231549.dat"="8/24/2016 8:08 AM, 28672 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\os_info Adds the file db_0.db"="9/7/2016 8:59 AM, 3072 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\os_info\temp Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\script_exec\temp Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\steam Adds the file db_0.db"="9/7/2016 8:58 AM, 5120 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\steam\temp Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\torrents Adds the file db_0.db"="9/7/2016 8:58 AM, 2048 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\torrents\temp Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\vk_web Adds the file db_0.db"="9/7/2016 8:58 AM, 7168 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\vk_web\temp Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\yahoo Adds the file db_0.db"="9/7/2016 8:58 AM, 7168 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\nsData\yahoo\temp Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MediaData] "SvcName"="REG_SZ", "ns" "userid"="REG_SZ", "97d23d8d09cfc942a9ef5f08edcdd8ec41701e6dc7ca5c9cc58fd89662e02082" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ns] "DisplayName"="REG_SZ", "ns" "DisplayVersion"="REG_SZ", "0.0.125" "InstallLocation"="REG_SZ", "C:\Program Files (x86)\ns\" "Publisher"="REG_SZ", "ns" "UninstallString"="REG_EXPAND_SZ, "C:\Program Files (x86)\ns\Uninstaller.exe" "VersionMajor"="REG_SZ", "0" "VersionMinor"="REG_SZ", "0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\ns] "Description"="REG_SZ", "ns" "DisplayName"="REG_SZ", "ns" "ErrorControl"="REG_DWORD", 1 "FailureActions"="REG_BINARY, ...................... "FailureCommand"="REG_SZ", "C:\Program Files (x86)\ns\ns.exe crashed" "ImagePath"="REG_EXPAND_SZ, "C:\Program Files (x86)\ns\ns.exe" "ObjectName"="REG_SZ", "LocalSystem" "Start"="REG_DWORD", 2 "Type"="REG_DWORD", 272 "WOW64"="REG_DWORD", 1Malwarebytes Anti-Malware log:
Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 9/7/2016 Scan Time: 9:08 AM Logfile: mbamNS.txt Administrator: Yes Version: 2.2.1.1043 Malware Database: v2016.09.07.01 Rootkit Database: v2016.08.15.01 License: Premium Malware Protection: Disabled Malicious Website Protection: Enabled Self-protection: Enabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {username} Scan Type: Threat Scan Result: Completed Objects Scanned: 319847 Time Elapsed: 9 min, 17 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 2 PUP.Optional.MediaForest, C:\Program Files (x86)\ns\ns.exe, 192, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e] PUP.Optional.MediaForest, C:\Program Files (x86)\ns\ns.exe, 3636, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e] Modules: 30 PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_bzip2-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_bzip2-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_chrono-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_chrono-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_date_time-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_date_time-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_filesystem-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_filesystem-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_iostreams-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_iostreams-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_system-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_system-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_thread-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_thread-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\cpprest120_xp_2_6.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\cpprest120_xp_2_6.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\libeay32.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\libeay32.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\libesedb.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\libesedb.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\lua53.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\lua53.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\msvcp120.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\msvcp120.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\msvcr120.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\msvcr120.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\ssleay32.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\ssleay32.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\zlib.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\zlib.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], Registry Keys: 2 PUP.Optional.MediaForest, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ns, Quarantined, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ns, Quarantined, [5fee1659acee3afc37e923c148bc728e], Registry Values: 0 (No malicious items detected) Registry Data[b]:[/b] 0 (No malicious items detected) Folders: 1 PUP.Optional.MediaForest, C:\Program Files (x86)\ns, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], Files: 19 Adware.Agent, C:\Users\{username}\Desktop\ns.exe, Quarantined, [6ae3c3ac257594a2608727bd758f3bc5], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\EULA.txt, Quarantined, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_bzip2-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_chrono-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_date_time-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_filesystem-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_iostreams-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_system-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\boost_thread-vc120-mt-1_59.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\cpprest120_xp_2_6.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\libeay32.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\libesedb.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\lua53.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\msvcp120.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\msvcr120.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\ns.exe, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\ssleay32.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\Uninstaller.exe, Quarantined, [5fee1659acee3afc37e923c148bc728e], PUP.Optional.MediaForest, C:\Program Files (x86)\ns\zlib.dll, Delete-on-Reboot, [5fee1659acee3afc37e923c148bc728e], Physical Sectors: 0 (No malicious items detected) (end)As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
- Dynamically Blocks Malware Sites & Servers
- Malware Execution Prevention