networx.exe

NetWorx

SOFTPERFECT PTY. LTD.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘NetWorx’.
Publisher:
SoftPerfect Research  (signed by SOFTPERFECT PTY. LTD.)

Product:
NetWorx

Description:
NetWorx Application (32-bit)

Version:
5.2.12.14023

MD5:
2c130489f0342bd6d059efd560b0f4d4

SHA-1:
f921254318929c911df1b84875e659bf1dcd1364

SHA-256:
b2954198fa4a60e96464cf1fd9f977884883943cc3b24a1ab14c7e50e4aea2b9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 9:46:24 AM UTC  (today)

File size:
3.3 MB (3,492,560 bytes)

Product version:
5.2.12.14023

Copyright:
2002-2014 SoftPerfect Research

File type:
Executable application (Win32 EXE)

Language:
English (Australia)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
9/17/2012 5:29:41 PM

Valid to:
12/17/2015 4:29:41 PM

Subject:
CN=SOFTPERFECT PTY. LTD., O=SOFTPERFECT PTY. LTD., L=KENSINGTON PARK, S=SOUTH AUSTRALIA, C=AU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121D3E3CF8CC5546295D1696F43CEF8BA42

File PE Metadata
Compilation timestamp:
1/23/2014 11:41:12 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:FUaexGPRSSez+9/8YrZ6pYZBOAU3qitsYEzIc5L8GJpZOsvnE:FjeJYZ9EqBlzIc5O

Entry address:
0x22E3E8

Entry point:
55, 8B, EC, B9, 04, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, 57, B8, 40, 3E, 62, 00, E8, 0B, CA, DD, FF, 33, C0, 55, 68, 48, E7, 62, 00, 64, FF, 30, 64, 89, 20, B8, 64, E7, 62, 00, E8, DB, 67, DF, FF, 84, C0, 74, 11, A1, 44, 75, 63, 00, 8B, 00, E8, EB, C6, F4, FF, E9, FB, 02, 00, 00, B8, 80, E7, 62, 00, E8, BC, 67, DF, FF, 84, C0, 74, 11, A1, 44, 75, 63, 00, 8B, 00, E8, 7C, CF, F4, FF, E9, DC, 02, 00, 00, B8, A0, E7, 62, 00, E8, 9D, 67, DF, FF, 84, C0, 75, 0E, B8, C0, E7, 62, 00, E8, 8F, 67, DF...
 
[+]

Entropy:
6.4797

Developed / compiled with:
Microsoft Visual C++

Code size:
2.2 MB (2,282,496 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NetWorx

Command:
"C:\Program Files\networx\networx.exe" \auto


Scan networx.exe - Powered by Reason Core Security