npmsvc.exe

Sowsoft LLC

It runs as a separate (within the context of its own process) windows Service named “Network Password Manager”.
Publisher:
Sowsoft LLC  (signed and verified)

MD5:
2b38a62fd05eb097c3f68c44ec4a7625

SHA-1:
5a08eb24a1d8fbe0e8362f072241abb4fd8a456b

SHA-256:
8a112e55e62fad22115e2a2002335e44477bd8783df8736a20ef1b2d2005b525

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 1:06:57 PM UTC  (today)

File size:
399.4 KB (408,968 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\network password manager\npmsvc.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
3/27/2007 5:30:00 AM

Valid to:
3/27/2009 5:29:59 AM

Subject:
CN=Sowsoft LLC, OU=(russian company name: ООО, O=Sowsoft LLC, STREET="Prospect Mira, d. 75, str. 1", L=Moscow, S=Moscow, PostalCode=129110, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
6EB1EE0573C8BD55A954D41E07F04B65

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:hdHmuh/knDAaeA1YWX3kshvUz0WHSuIUm:KuCMhAZn5hcfSNUm

Entry address:
0x1000

Entry point:
68, 01, 20, 4A, 00, E8, 01, 00, 00, 00, C3, C3, C8, 43, EF, 10, 51, F2, 43, 88, 49, F3, DF, 04, 62, 3C, D4, 6F, 06, 70, CB, EA, 6B, B6, 68, 1C, 10, AE, DE, 76, B4, BB, 2F, BC, 55, 3E, 82, 48, 2F, 45, 71, A8, 2C, 9F, D7, 31, D8, 21, 68, 65, 1D, 21, 16, 76, 31, 94, 73, 8A, C8, A1, 02, C8, D5, AE, D6, D8, 30, 3A, 78, 07, AE, 64, 4A, 04, A0, D0, 88, E3, B6, C4, D7, FC, 07, DD, 66, 1C, C8, 7E, 50, 85, A8, 90, 53, 46, 68, B6, 4B, EE, 17, 93, 22, F5, 5E, F7, 14, 2E, AC, E2, BF, 5A, 6E, 0B, FC, 3A, 5F, D7, C6, A5...
 
[+]

Entropy:
7.8235

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
501.5 KB (513,536 bytes)

Service
Display name:
Network Password Manager

Service name:
PassManager

Description:
PassManager service

Type:
Win32OwnProcess


Scan npmsvc.exe - Powered by Reason Core Security