qubnfe.exe

qubnfe

Quartzo Desenvolvimento de Software Ltda.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘qubnfe’. This file is installed with the program InterApp Control 3.55.
Publisher:
Quartzo Desenvolvimento de Software Ltda.  (signed by Quartzo Desenvolvimento de Software Ltda.)

Product:
qubnfe

Version:
3.05.0005

MD5:
b3b6a1f9f2c10a14659949af169a5e24

SHA-1:
d851d0d0b3784cf8821b0928ec401c209c0f4a46

SHA-256:
db4325104befbf6c0c3b0de2e4054655c9369c15cf93bde430bca0e8b8fe4d8c

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/25/2024 5:24:21 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Suspicious
19647

File size:
1.2 MB (1,219,928 bytes)

Product version:
3.05.0005

Original file name:
qubnfe.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\qubnfe\qubnfe.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
12/20/2012 10:35:17 AM

Valid to:
12/19/2013 4:51:54 PM

Subject:
CN=Quartzo Desenvolvimento de Software Ltda., OU=info@interapp.com.br, O=Quartzo Desenvolvimento de Software Ltda., L=Itatiba, S=SP, C=BR

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B88AE7E9F70E7

File PE Metadata
Compilation timestamp:
1/8/2013 12:12:29 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:5FxDbhqa2aUmnR7hmtKF7kuRtMAzogUDlCDtkYcZm2RInaFOe:F3VTfnR7hmtKOuTeIhU9

Entry address:
0x4776D0

Entry point:
60, BE, 00, 70, 75, 00, 8D, BE, 00, A0, CA, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 19, 8B, 1E, 83, EE, FC, 11, DB, 72, 10, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 78, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
1.1 MB (1,183,744 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
qubnfe

Command:
C:\Program Files\qubnfe\qubnfe.exe \auto


The file qubnfe.exe has been discovered within the following program.

InterApp Control 3.55  by Quartzo Software Ltda.
www.quartzo.com
About 1% of users remove it
 
Powered by Should I Remove It?

Scan qubnfe.exe - Powered by Reason Core Security