npav4.exe

Biz Secure Labs Pvt. Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘NPAV4’.
Publisher:
Biz Secure Lab Pvt. Ltd.  (signed by Biz Secure Labs Pvt. Ltd.)

Version:
2016, 2, 3, 0

MD5:
8f40af1edff040a071b4609eb19bc56a

SHA-1:
7f3faa0d23b0e65924011e6a6aca4835bf77a244

SHA-256:
d469f0f7c6be6182b4bb30d0018ba79d80286b1ce401e0503ac22f1dcc74623b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 6:28:16 PM UTC  (today)

File size:
560.7 KB (574,152 bytes)

Product version:
2016, 0, 0, 0

Copyright:
Copyright © 2012

Original file name:
npav4.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\net protector 2014\npav4.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/3/2013 11:19:26 PM

Valid to:
3/1/2017 6:03:38 PM

Subject:
E=support@indiaantivirus.com, CN=Biz Secure Labs Pvt. Ltd., O=Biz Secure Labs Pvt. Ltd., L=Pune, S=Maharashfra, C=IN

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121671B9C9C88B96999D212247766A5D404

File PE Metadata
Compilation timestamp:
2/3/2016 7:00:15 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:D8L3L+URuKmPwXMitRRF/cT2rFun4KzagSN+2+D1foZHrO:ozCUZmPwXM4zun5+gSm1fOHa

Entry address:
0x69AD

Entry point:
55, 8B, EC, 6A, FF, 68, B0, C1, 40, 00, 68, F0, 83, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 20, C1, 40, 00, 33, D2, 8A, D4, 89, 15, 44, 5C, 41, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 40, 5C, 41, 00, C1, E1, 08, 03, CA, 89, 0D, 3C, 5C, 41, 00, C1, E8, 10, A3, 38, 5C, 41, 00, 33, F6, 56, E8, 3B, 18, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, B0, 00, 00, 00, 59, 89, 75, FC, E8, 58, 16, 00, 00, FF, 15, 1C, C1, 40, 00, A3, 64, 71, 41, 00, E8...
 
[+]

Entropy:
5.5866

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
44 KB (45,056 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NPAV4

Command:
"C:\Program Files\net protector 2014\npav4.exe"


Scan npav4.exe - Powered by Reason Core Security