nfwd.exe

nfwd

Internet Rimon Israel 2009 LTD

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘RUNSVCHOST’.
Publisher:
Internet Rimon Israel 2009 LTD  (signed and verified)

Product:
nfwd

Version:
1.0.0.0

MD5:
4180fc6d0700ab03fee9445576355813

SHA-1:
3d437d4fe475ca85d99799a073f96df49bea0263

SHA-256:
b17f058c5c94c84546c5a5af8bdac423c537369a19c676e2cac8e8f49d4a0e3a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/6/2024 6:31:36 AM UTC  (today)

File size:
62.4 KB (63,864 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2010

Original file name:
nfwd.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/8/2016 7:59:38 PM

Valid to:
8/9/2019 7:59:38 PM

Subject:
CN=Internet Rimon Israel 2009 LTD, O=Internet Rimon Israel 2009 LTD, L=Givat Shmuel, S=Israel, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G3, O=GlobalSign nv-sa, C=BE

Serial number:
22EEB0CC19BD7AFEC336F4B5

File PE Metadata
Compilation timestamp:
12/25/2016 8:53:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
48.0

.NET CLR dependent:
Yes

Entry address:
0xEAEA

Entry point:
FF, 25, 00, 20, 40, 00, 5C, 00, 00, 00, 01, 00, 00, 00, 04, 00, 00, 00, 00, 10, 00, 00, 03, 00, 00, 00, 01, 00, 00, 00, 14, 00, 00, 00, 1E, CF, 5F, F1, EC, B6, 6B, 61, 1F, 7E, CA, DA, B6, EA, 97, 9C, 02, E2, 24, C6, 19, 00, 00, 00, 01, 00, 00, 00, 10, 00, 00, 00, FF, 51, 94, 49, D6, 88, 5A, 4D, 38, 06, 1F, EA, 3C, 74, 93, 90, 14, 00, 00, 00, 01, 00, 00, 00, 14, 00, 00, 00, 1D, 9D, C6, 15, 93, 95, B0, 46, 02, 96, 43, 56, C0, C6, 22, 7D, C5, 03, 2F, A5, 0F, 00, 00, 00, 01, 00, 00, 00, 40, 00, 00, 00, 67, F5...
 
[+]

Entropy:
5.8799

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
53 KB (54,272 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RUNSVCHOST

Command:
C:\internetrimon\nfwd.exe


Scan nfwd.exe - Powered by Reason Core Security