Ginfosrv.exe

Информационная система Гранд Строй-Инфо

LLC Centr GRAND

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘GrandStroyInfo’.
Publisher:
Центр по разработке и внедрению информационных технологий "Гранд"  (signed by LLC Centr GRAND)

Product:
Информационная система Гранд Строй-Инфо

Description:
Гранд Строй-Инфо Сервер

Version:
4.3.2.3907

MD5:
8571d9b6bbe07604bb5c90019db3ff09

SHA-1:
61e32a979e50024c2a2a9585df4cff7958bf7bfa

SHA-256:
3e10872e9ec9d06bb5bb3462dab6e220d2b67c8c9b6051fd0f1f55218cb841ec

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 6:45:47 PM UTC  (today)

File size:
4.4 MB (4,597,568 bytes)

Product version:
4.3.2

Copyright:
Центр "Гранд" г. Москва 1999 - 2011

Trademarks:
Центр "Гранд"

Original file name:
Ginfosrv.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\grand\stroyinfo\server\ginfosrv.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/22/2010 10:00:00 AM

Valid to:
10/22/2011 9:59:59 AM

Subject:
CN=LLC Centr GRAND, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=LLC Centr GRAND, L=Moscow, S=Moscow, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
46EF27AAEE26709F4684F1ECBC58916E

File PE Metadata
Compilation timestamp:
5/10/2011 5:52:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:+dLNbH+FRJPuuTgrqx9xWodoXc7SzsC3K1e3:cBjqR1u0qeluM7SYC3KQ3

Entry address:
0xA6628E

Entry point:
E8, 3B, FF, FF, FF, 05, 76, 27, 00, 00, FF, E0, E8, 2F, FF, FF, FF, 05, 3A, 0E, 00, 00, FF, E0, E8, 04, 00, 00, 00, FF, FF, FF, FF, 5E, C3, 00, 06, 9C, CC, 9C, 38, 2E, C0, 2F, AE, 5E, 4B, 8C, 42, 24, 08, 7E, 1C, A4, 79, FE, 6F, BB, D8, 0D, 44, 65, F8, 40, DA, 2F, 71, 56, AB, D2, 8A, 4B, A3, 6B, 8F, 1D, 71, 0A, 80, D9, 4B, B6, 0C, EB, B3, E2, 05, 31, DB, 74, F6, C0, 5E, 8F, 6D, 5D, 4E, 86, 23, 42, FF, 03, A0, B4, 3C, 5E, 35, 88, 24, 0E, EC, 85, 94, 7D, 0B, 4F, 18, F2, AE, A0, 14, 0E, 22, B0, 13, 5D, 3D, A0...
 
[+]

Code size:
3.3 MB (3,417,088 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
GrandStroyInfo

Command:
C:\Program Files\grand\stroyinfo\server\ginfosrv.exe


Scan Ginfosrv.exe - Powered by Reason Core Security