qubnfe.exe

qubnfe

Quartzo Desenvolvimento de Software Ltda.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘qubnfe’.
Publisher:
Quartzo Desenvolvimento de Software Ltda.  (signed by Quartzo Desenvolvimento de Software Ltda.)

Product:
qubnfe

Version:
3.07.0003

MD5:
57277c0bd04d0f7c5ab742676956ba85

SHA-1:
3849b6f8d38628cddf1dc5af31a64770d7026899

SHA-256:
5be64843046c4e3f28d392b3a047979a86c8f57cb6926a972ba3c5f7afe0989f

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
12/25/2024 6:11:35 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Suspicious
18157

F-Prot
W32/VBTrojan.17D1
4.6.5.141

File size:
1.4 MB (1,502,552 bytes)

Product version:
3.07.0003

Original file name:
qubnfe.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\qubnfe\qubnfe.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
12/20/2012 10:35:17 AM

Valid to:
12/19/2013 4:51:54 PM

Subject:
CN=Quartzo Desenvolvimento de Software Ltda., OU=info@interapp.com.br, O=Quartzo Desenvolvimento de Software Ltda., L=Itatiba, S=SP, C=BR

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B88AE7E9F70E7

File PE Metadata
Compilation timestamp:
8/30/2013 9:47:19 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:sykSLsNyc/Fhb1UVjDrjuJR6oo7nfidROUsgB5/c9xAMimP6SVzjlTZZLwiP:hkSQNT9t1U9DrjufIqdROUsyHmPJVzz/

Entry address:
0x4E57D0

Entry point:
60, BE, 00, 00, 78, 00, 8D, BE, 00, 10, C8, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 19, 8B, 1E, 83, EE, FC, 11, DB, 72, 10, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 78, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
1.4 MB (1,466,368 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
qubnfe

Command:
C:\Program Files\qubnfe\qubnfe.exe \auto


Scan qubnfe.exe - Powered by Reason Core Security