npesLauncher.exe

npesLauncher 응용 프로그램

INCA Internet. Co., Ltd.

Publisher:
INCA Internet. Co., Ltd.  (signed and verified)

Product:
npesLauncher 응용 프로그램

Version:
2008, 1, 7, 1

MD5:
88c6ad46a72ab2dd5ce7bb87434536e1

SHA-1:
5d8318402c2549e9d07021c4f21fe6e038a99cdc

SHA-256:
01f36ea3bae788daf6bd572c79ea5d40294c957144a5d0eea39a75571cbe1cd0

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/27/2024 12:57:32 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Virut.Gen
7.9.0.74

File size:
333.5 KB (341,552 bytes)

Product version:
2008, 1, 7, 1

Copyright:
Copyright (C) 2007

Original file name:
npesLauncher.exe

File type:
Executable application (Win32 EXE)

Language:
Korean

Common path:
C:\Windows\System32\npeslauncher.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
2/9/2007 5:07:28 AM

Valid to:
2/23/2008 2:42:07 AM

Subject:
CN="INCA Internet. Co., Ltd.", OU=Development Department, O="INCA Internet. Co., Ltd.", L=SEOUL, S=GYEONGGI-DO, C=KR

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
69F1FFB4F6E991E9D38B15BB8B921E33

File PE Metadata
Compilation timestamp:
1/29/1987 10:38:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:EdhwM8PySawi0rHtWxtMM9FsFxZBrZa+fdpHDzLlB4zi:YhNgRWXMMgDZBo+fdph/

Entry address:
0x1C589

Entry point:
E8, A7, C7, 00, 00, E9, 16, FE, FF, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 84, 89, 43, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 85, C0, 5F, 89, 45, FC, 5E, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, F4, 70, 43, 00, C9, C2, 08, 00, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63, FC, FF, E0, 5B...
 
[+]

Entropy:
6.2575

Code size:
216 KB (221,184 bytes)

ActiveX Install
Name:
{4C68DACE-E6BC-4650-9C7E-D036720CA729}


Scan npesLauncher.exe - Powered by Reason Core Security