nfserv.exe

nfserv

Internet Rimon Israel 2009 LTD

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘RUNNFSERV’.
Publisher:
Internet Rimon Israel 2009 LTD  (signed and verified)

Product:
nfserv

Version:
1.0.0.0

MD5:
68cbb57a55322bbf6ba2a1421a713afb

SHA-1:
2c65c4e4fa96faa6636262cd3efb6fc555ccdabf

SHA-256:
2e76eed6962f32b3710459a24dea5839c90473e00c16663c26581edac0457396

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 11:29:53 AM UTC  (today)

File size:
461.6 KB (472,688 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2010

Original file name:
nfserv.exe

File type:
Executable application (Win64 EXE)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/3/2014 4:06:21 PM

Valid to:
3/3/2017 4:06:21 PM

Subject:
CN=Internet Rimon Israel 2009 LTD, O=Internet Rimon Israel 2009 LTD, L=Givat Shmuel, S=Israel, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E009CE6A8C6688EC6901BAD45E51B46F

File PE Metadata
Compilation timestamp:
7/24/2016 11:52:31 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
48.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:5OhlB7IM4nHXcJbjxT/qNL8w9JyrkelAZX6FJSebrnK8w909VcIkuZ8IpV:sERcvTC8y8rke2ZuMebu8yoVc4Z8IH

Entry address:
0x72D52

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.7232

Code size:
453.5 KB (464,384 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RUNNFSERV

Command:
C:\internetrimon\nfserv.exe


Scan nfserv.exe - Powered by Reason Core Security