nfserv.exe

nfserv

Internet Rimon Israel 2009 LTD

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘RUNNFSERV’.
Publisher:
Internet Rimon Israel 2009 LTD  (signed and verified)

Product:
nfserv

Version:
1.0.0.0

MD5:
97bafeff0c68dea164316a6b57955111

SHA-1:
f83c34b7be6b773c36895d3b43f4ff07fd42b743

SHA-256:
cbff137b9301073f729555709e0315a8db7580bf64577f8e04a389d60a81b396

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/6/2024 6:25:57 AM UTC  (today)

File size:
463.4 KB (474,488 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2010

Original file name:
nfserv.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/8/2016 7:59:38 PM

Valid to:
8/9/2019 7:59:38 PM

Subject:
CN=Internet Rimon Israel 2009 LTD, O=Internet Rimon Israel 2009 LTD, L=Givat Shmuel, S=Israel, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G3, O=GlobalSign nv-sa, C=BE

Serial number:
22EEB0CC19BD7AFEC336F4B5

File PE Metadata
Compilation timestamp:
12/25/2016 8:53:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
48.0

.NET CLR dependent:
Yes

Entry address:
0x72D36

Entry point:
FF, 25, 00, 20, 40, 00, 5C, 00, 00, 00, 01, 00, 00, 00, 04, 00, 00, 00, 00, 10, 00, 00, 03, 00, 00, 00, 01, 00, 00, 00, 14, 00, 00, 00, 1E, CF, 5F, F1, EC, B6, 6B, 61, 1F, 7E, CA, DA, B6, EA, 97, 9C, 02, E2, 24, C6, 19, 00, 00, 00, 01, 00, 00, 00, 10, 00, 00, 00, FF, 51, 94, 49, D6, 88, 5A, 4D, 38, 06, 1F, EA, 3C, 74, 93, 90, 14, 00, 00, 00, 01, 00, 00, 00, 14, 00, 00, 00, 1D, 9D, C6, 15, 93, 95, B0, 46, 02, 96, 43, 56, C0, C6, 22, 7D, C5, 03, 2F, A5, 0F, 00, 00, 00, 01, 00, 00, 00, 40, 00, 00, 00, 67, F5...
 
[+]

Entropy:
6.7251

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
453.5 KB (464,384 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RUNNFSERV

Command:
C:\internetrimon\nfserv.exe


Scan nfserv.exe - Powered by Reason Core Security