nspmain.exe

nProtect Anti-Virus/Spyware

INCA Internet Co.,Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘nProtect GameGuard Personal 3.0’.
Publisher:
INCA Internet Co., Ltd.  (signed by INCA Internet Co.,Ltd.)

Product:
nProtect Anti-Virus/Spyware

Description:
nProtect Anti-Virus/Spyware Main Application

Version:
3.0.12929.0

MD5:
0052328e0aa46fd3d350d71cd5a7666b

SHA-1:
75fbd3eea5aa5d238d821c05c6034035ed83e017

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 3:32:31 PM UTC  (today)

File size:
1.1 MB (1,104,488 bytes)

Product version:
3.0.12929.0

Copyright:
(C) INCA Internet Inc. All rights reserved.

Original file name:
nspmain.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\incainternet\nprotect gameguard personal 3.0\nspmain.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/2/2011 7:00:00 AM

Valid to:
12/7/2012 6:59:59 AM

Subject:
CN="INCA Internet Co.,Ltd.", OU=Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="INCA Internet Co.,Ltd.", L=Seoul, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
233C35EED5F9F575BA46FABC8D47CB6E

File PE Metadata
Compilation timestamp:
1/30/1987 10:38:08 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:9FfyB4KDFpOU/LTd/pRgDbww22Us/rV+4TmNmwsZn7mOyPEk7F37VlJmb3sKNdqf:KJpBVkhWMEzx537VlMu8EswjLjnSjZk

Entry address:
0xBB66C

Entry point:
E8, B7, 07, 00, 00, E9, DA, FC, FF, FF, FF, 25, BC, 7B, 4C, 00, 3B, 0D, 84, FD, 4E, 00, 75, 02, F3, C3, E9, 31, 08, 00, 00, 8B, C1, C7, 00, BC, B7, 4D, 00, C2, 04, 00, 53, 8A, 5C, 24, 08, F6, C3, 02, 56, 8B, F1, 74, 24, 57, 68, B4, C0, 4B, 00, 8D, 7E, FC, FF, 37, 6A, 0C, 56, E8, EE, 01, 00, 00, F6, C3, 01, 74, 07, 57, E8, E5, F1, FF, FF, 59, 8B, C7, 5F, EB, 13, E8, E8, 09, 00, 00, F6, C3, 01, 74, 07, 56, E8, CF, F1, FF, FF, 59, 8B, C6, 5E, 5B, C2, 04, 00, 8B, C1, C2, 04, 00, FF, 25, B8, 7B, 4C, 00, FF, 25...
 
[+]

Entropy:
6.1489

Code size:
792 KB (811,008 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
nProtect GameGuard Personal 3.0

Command:
C:\Program Files\incainternet\nprotect gameguard personal 3.0\nspmain.exe -tray


Scan nspmain.exe - Powered by Reason Core Security