ndservice.exe

Secpa Yazilim Bilgisayar Internet Tek. ve Ins.San. Tic.Ltd.Sti.

It runs as a separate (within the context of its own process) windows Service named “Internet Filter Service”.
Description:
WebAynet Inject Service

Version:
2.0.1.12

MD5:
2ea285011348e843e70a7a06204b3399

SHA-1:
594bc260110335a51559f0f295b3d45f0acc1943

SHA-256:
508b9c9e2dd050f574da54b2744da07837ea1dadc39ebb18af1cb4594c92e016

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
5/10/2024 7:56:22 AM UTC  (today)

Scan engine
Detection
Engine version

Trend Micro House Call
Mal_Xed-21
7.2.322

Trend Micro
Mal_Xed-21
10.465.18

File size:
4.7 MB (4,891,192 bytes)

Product version:
2.0.1.12

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\netdadifree\ndservice.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
2/12/2013 5:03:05 PM

Valid to:
2/13/2014 5:03:05 PM

Subject:
CN=Secpa Yazilim Bilgisayar Internet Tek. ve Ins.San. Tic.Ltd.Sti., O=Secpa Yazilim Bilgisayar Internet Tek. ve Ins.San. Tic.Ltd.Sti., L=Beylikduzu, S=Istanbul, C=TR

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121C0151F6D8DF30F48AA92AA553CB68ABA

File PE Metadata
Compilation timestamp:
6/5/2013 10:35:09 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:SCRRpb80J03/X8WMN5ivu/1OJSRpakHIxEYRCdy2JVa8gfMEf4TBawGEcS3:ZRP3Kvhc5r/m2paLFMdpJE8g0Ef4E2cS

Entry address:
0x26C1AA

Entry point:
52, BA, 64, 00, 00, 00, 85, D2, 74, 46, B9, 00, 10, 00, 00, 85, C9, 74, 08, 01, C8, 01, D8, FF, C9, EB, F4, 52, 48, 83, EC, 20, 48, C7, 04, 24, 00, 00, 00, 00, 48, C7, 44, 24, 08, 00, 00, 00, 00, 48, 89, E1, 48, 89, E2, 48, 83, C2, 08, 48, B8, 68, E4, E4, 00, 00, 00, 00, 00, FF, 10, 48, 83, C4, 20, 5A, FF, CA, EB, B6, 5A, E9, 00, FE, B3, 00, 00, 00, 00, 00, 64, 54, C5, 42, 00, 00, 00, 00, 02, 00, 09, 00, 78, 19, 00, 80, 68, 00, 00, 80, A2, 19, 00, 80, D8, 00, 00, 80, 01, 00, 00, 00, 08, 02, 00, 80, 02, 00...
 
[+]

Code size:
7.2 MB (7,586,816 bytes)

Service
Display name:
Internet Filter Service

Service name:
IntFiltrService

Type:
Win32OwnProcess


Scan ndservice.exe - Powered by Reason Core Security