npmsvc.exe

Sowsoft LLC

It runs as a separate (within the context of its own process) windows Service named “Network Password Manager”.
Publisher:
Sowsoft LLC  (signed and verified)

MD5:
aad51ae1efb403b7a6bceaffbf4aa476

SHA-1:
0a735141bc8f7bf23db53bfe822df98e3ca39fef

SHA-256:
ae81b16f46cf120abe4ce695ff63629adff57d93f5dcceabe350e01e24b490ed

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 3:30:11 PM UTC  (today)

File size:
397.9 KB (407,432 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\network password manager\npmsvc.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
3/26/2007 7:00:00 PM

Valid to:
3/26/2009 6:59:59 PM

Subject:
CN=Sowsoft LLC, OU=(russian company name: ООО, O=Sowsoft LLC, STREET="Prospect Mira, d. 75, str. 1", L=Moscow, S=Moscow, PostalCode=129110, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
6EB1EE0573C8BD55A954D41E07F04B65

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x1000

Entry point:
68, 01, 20, 4A, 00, E8, 01, 00, 00, 00, C3, C3, C8, 43, EF, 10, 28, 4A, 71, EF, 6E, DE, 67, B0, B5, 39, 72, 5E, 6F, C3, 65, 6F, 2A, A5, 8A, 1C, 10, AE, 52, 16, 98, 33, 2F, BE, EE, 5E, AA, 3A, BF, 4D, F8, 09, 4F, A5, D8, DC, FA, C9, D7, D7, 42, 21, A8, 6D, C4, 53, D0, B6, B0, FE, A4, AA, AB, 4A, 42, 8A, 7B, EF, B4, 85, 22, CD, E2, 19, 65, D3, E7, FD, 85, F5, 6E, 30, 05, 85, FB, 3A, D9, 34, 34, D4, 81, B0, 06, 18, 5E, AA, 62, 2F, 53, A8, 24, D6, DF, 73, 2D, 34, CD, 1A, AF, CB, 2C, 03, B4, 94, D3, DB, 3E, F0...
 
[+]

Entropy:
7.8227

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
502.5 KB (514,560 bytes)

Service
Display name:
Network Password Manager

Service name:
PassManager

Description:
PassManager service

Type:
Win32OwnProcess


Scan npmsvc.exe - Powered by Reason Core Security