nspmain.exe

nProtect Anti-Virus/Spyware

INCA Internet Co.,Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘nProtect GameGuard Personal 3.0’.
Publisher:
INCA Internet Co., Ltd.  (signed by INCA Internet Co.,Ltd.)

Product:
nProtect Anti-Virus/Spyware

Description:
nProtect Anti-Virus/Spyware Main Application

Version:
3.0.13346.0

MD5:
969fb79e91d3f3acf1e2836f81c2cd44

SHA-1:
2f4411ac631b4fe5775644f2052d2260c647899b

SHA-256:
bae5ab16c272bbd05382f8dc6c0d03a226c99032873abb4ab36ef79531de2c6d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 7:25:15 AM UTC  (today)

File size:
1.3 MB (1,313,984 bytes)

Product version:
3.0.13346.0

Copyright:
(C) INCA Internet Inc. All rights reserved.

Original file name:
nspmain.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\incainternet\nprotect gameguard personal 3.0\nspmain.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/23/2013 7:00:00 AM

Valid to:
1/23/2015 6:59:59 AM

Subject:
CN="INCA Internet Co.,Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="INCA Internet Co.,Ltd.", L=Seoul, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
604C797CBABB63D6D0FF81C7CA93DA57

File PE Metadata
Compilation timestamp:
1/30/1987 10:38:08 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:BDjs6dh+MPyELLk8CXkTAMtIvoPfn1UJWisEOkEcarAer3kbN6y+d2WewUL+a6dY:3J64LwsZ6dLR6dVwMWydf3rsnTZF/Hyu

Entry address:
0xBD582

Entry point:
E8, 41, 09, 00, 00, E9, DA, FC, FF, FF, FF, 25, D4, 9B, 4C, 00, 3B, 0D, 84, 1D, 4F, 00, 75, 02, F3, C3, E9, BB, 09, 00, 00, 8B, C1, C7, 00, 04, DA, 4D, 00, C2, 04, 00, 53, 8A, 5C, 24, 08, F6, C3, 02, 56, 8B, F1, 74, 24, 57, 68, 54, E1, 4B, 00, 8D, 7E, FC, FF, 37, 6A, 0C, 56, E8, F8, 01, 00, 00, F6, C3, 01, 74, 07, 57, E8, DF, F1, FF, FF, 59, 8B, C7, 5F, EB, 13, E8, 72, 0B, 00, 00, F6, C3, 01, 74, 07, 56, E8, C9, F1, FF, FF, 59, 8B, C6, 5E, 5B, C2, 04, 00, 8B, C1, C2, 04, 00, FF, 25, D0, 9B, 4C, 00, FF, 25...
 
[+]

Entropy:
5.8494

Code size:
800 KB (819,200 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
nProtect GameGuard Personal 3.0

Command:
C:\Program Files\incainternet\nprotect gameguard personal 3.0\nspmain.exe -tray


Scan nspmain.exe - Powered by Reason Core Security