nfserv.exe

nfserv

Internet Rimon Israel 2009 LTD

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘RUNNFSERV’.
Publisher:
Internet Rimon Israel 2009 LTD  (signed and verified)

Product:
nfserv

Version:
1.0.0.0

MD5:
58053a94602479e6f52d97136074dbdc

SHA-1:
9295bc3a16f494ef8761969119eb04053b722454

SHA-256:
f206243ae816fcec56f21c6d894921e59b3d9a010c755cf98831ab6b1bfe5a8f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/6/2024 4:31:57 AM UTC  (today)

File size:
460.6 KB (471,664 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2010

Original file name:
nfserv.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/3/2014 4:06:21 PM

Valid to:
3/3/2017 4:06:21 PM

Subject:
CN=Internet Rimon Israel 2009 LTD, O=Internet Rimon Israel 2009 LTD, L=Givat Shmuel, S=Israel, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E009CE6A8C6688EC6901BAD45E51B46F

File PE Metadata
Compilation timestamp:
1/21/2015 10:54:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:DIQblp+YzFtLH5V8w91yraVtAoX6FJSebrnK8w909KcIkuZRTjb3m9Y/QZ3eD:f/78yoraVuouMebu8yoKc4ZJNg8

Entry address:
0x7301E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.7099

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
452.5 KB (463,360 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RUNNFSERV

Command:
C:\internetrimon\nfserv.exe


Scan nfserv.exe - Powered by Reason Core Security