nsearcher.exe

Netimo Navigator

Netimo Corporation Ltd.

The application nsearcher.exe by Netimo has been detected as a potentially unwanted program by 5 anti-malware scanners.
Publisher:
Netimo Communications Co. Ltd.  (signed by Netimo Corporation Ltd.)

Product:
Netimo Navigator

Version:
1.01.0500

MD5:
6f9e933147ce14dc70db4b1f6911fde0

SHA-1:
2ce94f02b4bab1fdc150f942c4acf18ea5741fc7

SHA-256:
6f81be58fc36cc46f87eadf7bbafc6fabe42ac04068542ab177dd94edb034e0d

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 1:05:52 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
UnclassifiedMalware
18308

Dr.Web
BACKDOOR.Trojan
9.0.1.0213

ESET NOD32
Win32/AdWare.Kraddare.JZ (variant)
8.9833

Malwarebytes
Adware.Netimo
v2014.08.01.12

McAfee
Artemis!6F9E933147CE
5600.7052

File size:
234.6 KB (240,216 bytes)

Product version:
1.01.0500

Trademarks:
Netimo Navigator

Original file name:
ntmurl.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\nsearcher.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
3/22/2013 9:00:00 AM

Valid to:
6/22/2015 8:59:59 AM

Subject:
CN=Netimo Corporation Ltd., O=Netimo Corporation Ltd., L=Mapo-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6BF1CF3F23D51761F7B88C6C00CC69AD

File PE Metadata
Compilation timestamp:
3/26/2013 4:13:11 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:PdYM5Wh0sGfSm/IZ3AP+JnUD1KwCysoMtsiS0UW4YxaaWR:1n60QZczUwCys7DS0N4YxW

Entry address:
0x4A40

Entry point:
68, 60, 4E, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 50, 00, 00, 00, 38, 00, 00, 00, 3B, 5F, 1C, B0, 95, AA, 7C, 48, B2, 8E, 38, A3, 3B, 11, 92, EA, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 5F, 4E, 41, 4D, 45, 5F, 6E, 74, 6D, 55, 52, 4C, 00, 20, 4E, 65, 74, 69, 6D, 6F, 20, 4E, 61, 76, 69, 67, 61, 74, 6F, 72, 00, 6E, 67, 20, 3D, 20, 31, 32, 00, 00, 00, 00, 01, 00, 03, 00, C4, 5B, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, A8, 5C, 40, 00, 48, 50, 43, 00...
 
[+]

Entropy:
5.8165

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
208 KB (212,992 bytes)

Remove nsearcher.exe - Powered by Reason Core Security