nfserv.exe

nfserv

Internet Rimon Israel 2009 LTD

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘RUNNFSERV’.
Publisher:
Internet Rimon Israel 2009 LTD  (signed and verified)

Product:
nfserv

Version:
1.0.0.0

MD5:
67eec7243ae0797c337c0b1a56ce1f15

SHA-1:
c84b1f7e02297c36de9a28311238e6474e21c03e

SHA-256:
f75d85f4b4d0795ffc6e282be6d3ce6b07b118a7ca58817d2f6adbaf868f84ee

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 11:32:15 AM UTC  (today)

File size:
462.1 KB (473,200 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2010

Original file name:
nfserv.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/3/2014 4:06:21 PM

Valid to:
3/3/2017 4:06:21 PM

Subject:
CN=Internet Rimon Israel 2009 LTD, O=Internet Rimon Israel 2009 LTD, L=Givat Shmuel, S=Israel, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E009CE6A8C6688EC6901BAD45E51B46F

File PE Metadata
Compilation timestamp:
6/3/2015 2:37:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:7cN86clayEaqv4W2REznPfmPfteU4yoCwy+JJLvKI9GmfRZS2qNwIoA8G9zfO8w7:Q+bmZtum8yM5EvkW4AQbm8yiAcKZBwu

Entry address:
0x7376E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.7082

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
454 KB (464,896 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RUNNFSERV

Command:
C:\internetrimon\nfserv.exe


Scan nfserv.exe - Powered by Reason Core Security