qubnfe.exe

qubnfe

Quartzo Desenvolvimento de Software Ltda.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘qubnfe’.
Publisher:
Quartzo Desenvolvimento de Software Ltda.  (signed by Quartzo Desenvolvimento de Software Ltda.)

Product:
qubnfe

Version:
3.05.0009

MD5:
419b125cdf3a5febb38387f93d9f8da6

SHA-1:
2dc053af145473e53e73f52b3b2b51ef5d3a0950

SHA-256:
c28823498c288ff85e95ffe394367990bdd02f7b0d6adbefd1d7fe86022c6fab

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/25/2024 6:02:16 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Suspicious
18148

File size:
1.4 MB (1,465,688 bytes)

Product version:
3.05.0009

Original file name:
qubnfe.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\qubnfe\qubnfe.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
12/20/2012 10:35:17 AM

Valid to:
12/19/2013 4:51:54 PM

Subject:
CN=Quartzo Desenvolvimento de Software Ltda., OU=info@interapp.com.br, O=Quartzo Desenvolvimento de Software Ltda., L=Itatiba, S=SP, C=BR

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B88AE7E9F70E7

File PE Metadata
Compilation timestamp:
3/14/2013 8:31:19 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:cz/fcv5FPVpaE3aN9Q2WpGJg+IfsXxUVJcj4d/2OFFOsPlAVZB/AvOStPqLDDll:cTfw5FPVp9aN9mInXxEJaJOpUB/qtPqb

Entry address:
0x4E36B0

Entry point:
60, BE, 00, 70, 78, 00, 8D, BE, 00, A0, C7, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 19, 8B, 1E, 83, EE, FC, 11, DB, 72, 10, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 78, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
1.4 MB (1,429,504 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
qubnfe

Command:
C:\Program Files\qubnfe\qubnfe.exe \auto


Scan qubnfe.exe - Powered by Reason Core Security