npmsvc.exe

Sowsoft LLC

It runs as a separate (within the context of its own process) windows Service named “Network Password Manager”.
Publisher:
Sowsoft LLC  (signed and verified)

MD5:
6365d663e8db2f5e2dcba3ae1ad7a9c4

SHA-1:
6c0095022b169dc4bc46d075e098429834e1aa2c

SHA-256:
924bdbdafa8b7c8f310384ca9a87276260555b7fce28931ea0d529e715901734

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 9:08:58 AM UTC  (today)

File size:
445.5 KB (456,144 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\network password manager\npmsvc.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
3/23/2009 12:00:00 AM

Valid to:
3/23/2011 11:59:59 PM

Subject:
CN=Sowsoft LLC, O=Sowsoft LLC, STREET="Prospect Mira, d. 75, str. 1", L=Moscow, S=Moscow, PostalCode=129110, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
042E3AD215DF337FD2A69CD2F3F9111B

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:Smm51Txi3M4TiJhGwfNArdWoWPCZHBLL6YxN6PLa:vmfTx4M4mJhA7WPCVB36Yv6O

Entry address:
0x1000

Entry point:
68, 01, C0, 4A, 00, E8, 01, 00, 00, 00, C3, C3, 6C, 3F, 1E, DB, 84, B5, 03, FD, 2F, 88, 27, 5C, FF, 6B, 8D, 0C, 71, 5F, B8, 27, E5, 65, 6C, B2, 8E, EB, 6B, 86, 17, 23, D3, 72, CB, 89, 9D, 3A, 66, 9B, AF, B0, A2, 90, 26, 30, DF, 14, 13, 90, C7, DF, 50, 47, 27, 7D, 89, DB, F5, DF, 36, BF, 68, 02, E9, 6A, C7, 49, BB, 0F, F5, DE, EC, BD, 7E, D9, 16, 25, 0D, 0A, FE, C9, EC, 7E, B1, 18, 5A, E1, 19, 5F, DC, FD, 6B, 6C, 09, 4B, 47, 3C, B7, F2, 96, 44, 46, 2A, 04, 71, A7, EE, 06, 71, 02, D9, 94, 56, 28, 1F, 7F, 55...
 
[+]

Entropy:
7.8600

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
536.5 KB (549,376 bytes)

Service
Display name:
Network Password Manager

Service name:
PassManager

Type:
Win32OwnProcess


Scan npmsvc.exe - Powered by Reason Core Security