nosejane.exe

Sivi Technology Limited

The application nosejane.exe by Sivi Technology Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Protect Service(NosejaneP)”.
Publisher:
Sivi Technology Limited  (signed and verified)

MD5:
7cf7f3d515cd76d9aa2eaaec4c924117

SHA-1:
045999c08dd0ccc4e2f288a4123bb3c5d47e617f

SHA-256:
ddf4fe4a5c4166be23a8fea7a0a27869568f6a010049a1e5bb29dff6b7cfcaab

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 9:31:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex (M)
16.7.15.10

File size:
419.9 KB (429,968 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\nosejane\nosejane.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/13/2016 9:57:45 PM

Valid to:
2/28/2017 11:56:03 PM

Subject:
CN=Sivi Technology Limited, O=Sivi Technology Limited, L=Hong Kong, S=Hong Kong, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G3, O=GlobalSign nv-sa, C=BE

Serial number:
08CE1D7B4F87FAE4994A1584

File PE Metadata
Compilation timestamp:
7/14/2016 11:09:41 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
6144:dAUNWu5Bu6tKkJPCV6Strwz3+L3SrZnGVKVOlnUZKpu/QAV+E:tWu5fOJO9nGtlu/vVp

Entry address:
0x2E6C4

Entry point:
AA, DD, 45, 00, 00, AB, C2, BC, BD, BD, BD, 67, 1E, B1, 06, 00, C9, 0F, B6, 26, CB, 4F, 00, 00, 00, 00, 1B, 1D, 1D, 1C, 19, C9, A7, 1F, 13, B0, 81, 12, 26, BD, 77, 00, 00, 00, 00, CF, 06, 66, 4E, 69, 26, 66, 4E, 11, 14, 15, CB, 6A, C9, AA, E3, FE, 73, 04, 00, 71, 87, 12, BD, 37, BE, 85, 07, BE, BD, BD, BD, BD, CF, 07, B6, 26, E1, 00, 00, 00, 00, B0, 81, 12, 26, BD, 77, 00, 00, 00, 00, CF, 06, 66, 4E, 69, 26, 66, 4E, 11, 14, 15, CB, 6A, C9, AA, E3, FE, 73, 04, 00, 71, 87, 12, CB, 27, B2, BD, 37, BE, 85, 07...
 
[+]

Entropy:
6.4452

Code size:
309.5 KB (316,928 bytes)

Service
Display name:
Protect Service(NosejaneP)

Service name:
NosejaneP

Description:
To ensure your Nosejane software integrity. If this service is disabled or stopped, your Nosejane software will not be kept integrity check. This service uninstalls itself when there is no Nosejane so

Type:
Win32OwnProcess

Depends on:
RpcSs


Remove nosejane.exe - Powered by Reason Core Security