npmsvc.exe

Sowsoft LLC

It runs as a separate (within the context of its own process) windows Service named “Network Password Manager”.
Publisher:
Sowsoft LLC  (signed and verified)

MD5:
cf92ff0f57d71524cb8f786f1fe1128d

SHA-1:
3227743f2dc02c7f4e0b374c1b6b0b42387e9076

SHA-256:
f215af8f14bab3f80e3f85032844ede940f2306a2336da1b3098942323f15928

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/25/2024 1:27:35 PM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
PUA.Packed.ASPack212
0.98/171

Quick Heal
(Suspicious) - DNAScan
5.16.10.00

File size:
439.4 KB (449,944 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\network password manager\npmsvc.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
3/22/2009 8:00:00 PM

Valid to:
3/23/2011 7:59:59 PM

Subject:
CN=Sowsoft LLC, O=Sowsoft LLC, STREET="Prospect Mira, d. 75, str. 1", L=Moscow, S=Moscow, PostalCode=129110, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
042E3AD215DF337FD2A69CD2F3F9111B

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:YGX1Me7JEoUDnTgBrKhhvuQGo4pRWIVlDOn+aCP0vdZhhL0MT37uoHWQfVqLyV1:PZWh7dhhvu9F/jziWPCZHBLLHWuoLyD

Entry address:
0x1000

Entry point:
68, 01, 70, 4A, 00, E8, 01, 00, 00, 00, C3, C3, 8D, 8C, 16, 3F, AF, 81, 9C, BD, 5A, DA, 91, 64, 6B, D3, A9, 1D, 75, AC, FA, 7E, CD, 73, 41, FD, 79, 59, 42, 7D, 35, 12, ED, 3D, 64, F4, E4, 66, 8A, D0, BF, 49, AB, 54, 8D, 8B, 0A, 97, 90, 5E, 0C, F4, 51, FC, EE, F9, 2F, 12, D2, 7B, EA, C1, 59, 2E, FE, C1, 31, 82, 37, B1, 3A, D8, D2, AB, FF, A2, 24, 8E, 50, 6F, B1, 0C, 9C, 10, AF, 57, BD, 29, E3, 0A, 88, 18, C8, 5C, D4, 39, A9, 2F, 55, FE, 86, 0B, 71, 31, BB, 36, BB, 01, 49, 6E, 5C, 4F, D4, 36, B0, A1, AA, 41...
 
[+]

Entropy:
7.8582

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
520.5 KB (532,992 bytes)

Service
Display name:
Network Password Manager

Service name:
PassManager

Type:
Win32OwnProcess


Scan npmsvc.exe - Powered by Reason Core Security