npmsvc.exe

Sowsoft LLC

It runs as a separate (within the context of its own process) windows Service named “Network Password Manager”.
Publisher:
Sowsoft LLC  (signed and verified)

MD5:
137d6b754c4312238d22b86752d71bfc

SHA-1:
e7a780b64617c07846ded4e80a6ce199eeb7d80f

SHA-256:
b53ec6523959b2d8e3d2db59dfc4ced326e5a3c90c0ca8c397c7260414f7b758

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 7:23:43 PM UTC  (today)

File size:
446.2 KB (456,952 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\network password manager\npmsvc.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/27/2011 6:00:00 PM

Valid to:
7/27/2013 5:59:59 PM

Subject:
CN=Sowsoft LLC, O=Sowsoft LLC, STREET="Prospect Mira, d.75, str. 1", L=Moscow, S=Moscow, PostalCode=129110, C=RU

Issuer:
CN=COMODO Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
10CDC7CCFE3D2396252D042EEE61DDF1

File PE Metadata
Compilation timestamp:
6/19/1992 4:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:dcpaxVxio0ULp2bCtsSqDih7oiOfHwFV34slSqt6lcOn+aCP0vdZhhL0MTW8zloV:dcgis2utsfCoHHGV3JlSthWPCZHBWzX

Entry address:
0x1000

Entry point:
68, 01, C0, 4A, 00, E8, 01, 00, 00, 00, C3, C3, 8D, 8C, 16, 3F, AD, 15, 2C, D1, 59, C2, E7, FD, FD, CE, 2C, 98, 51, 05, 84, F8, F9, 62, 6F, DE, 07, D5, 32, E9, B4, 1E, 88, B1, F5, 6E, D6, 6B, AF, 93, 66, 58, AA, 09, 9B, E5, 4C, 0D, FB, 91, 44, 6C, 5D, 55, 4E, 94, CB, A4, BF, 6F, 8D, B6, 8A, 2D, C9, 16, 51, 87, CA, 80, 20, 6B, 1E, AC, BC, 0B, F0, F4, 27, 56, CB, FB, D2, DE, 39, C9, 98, 33, 3A, E6, C0, EE, 95, BF, 69, 75, 8A, 6A, 6B, C3, B3, 1E, BA, FE, 04, CC, CA, 23, E7, 98, 1D, 98, A9, B6, 82, 4F, C5, F7...
 
[+]

Entropy:
7.8600

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
536.5 KB (549,376 bytes)

Service
Display name:
Network Password Manager

Service name:
PassManager

Type:
Win32OwnProcess


Scan npmsvc.exe - Powered by Reason Core Security