nwsvc.exe

NoAD Watchdog SDK

MirageWorks Inc.

It runs as a separate (within the context of its own process) windows Service named “MirageWorks2 Watchdog Service”.
Publisher:
NoAD Inc.  (signed by MirageWorks Inc.)

Product:
NoAD Watchdog SDK

Description:
NoAD Watchdog Service

Version:
1, 6, 0, 35310

MD5:
7d45052cee8b95426723ffa255913f21

SHA-1:
dc3ff70b37f8c8b5c02de88d6b5ee0a9c4417e64

SHA-256:
1682278d034b837efa9fde906524d46d8b5d3d64b28b9d34db35d7886a75606b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/20/2024 2:07:24 AM UTC  (today)

File size:
605.1 KB (619,656 bytes)

Product version:
1, 6, 0, 35310

Copyright:
Copyright (c) 2010 NoAD Inc., All rights reserved.

Original file name:
nwsvc.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\mirageworks2\nwsvc.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
11/2/2011 9:00:00 AM

Valid to:
11/2/2012 8:59:59 AM

Subject:
CN=MirageWorks Inc., OU=marketing, O=MirageWorks Inc., L=Mapo-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
01FFC3CE1D7C18F4FD6646EB3CF125D7

File PE Metadata
Compilation timestamp:
8/24/2012 6:44:48 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:ukWZjY3Gua1OMGvRrQzNVy3EGT6Mb8+EO7nFA:Qua1TEErgEGT6I8+EiFA

Entry address:
0x5349E

Entry point:
E8, 36, 07, 00, 00, E9, 6B, FD, FF, FF, FF, 25, AC, F3, 45, 00, 6A, 14, 68, 58, 0A, 47, 00, E8, 76, 06, 00, 00, FF, 35, 0C, 04, 48, 00, 8B, 35, 34, F1, 45, 00, FF, D6, 89, 45, E4, 83, F8, FF, 75, 0C, FF, 75, 08, FF, 15, 84, F3, 45, 00, 59, EB, 64, 6A, 08, E8, 9D, 07, 00, 00, 59, 83, 65, FC, 00, FF, 35, 0C, 04, 48, 00, FF, D6, 89, 45, E4, FF, 35, 08, 04, 48, 00, FF, D6, 89, 45, E0, 8D, 45, E0, 50, 8D, 45, E4, 50, FF, 75, 08, 8B, 35, 38, F1, 45, 00, FF, D6, 50, E8, 63, 07, 00, 00, 83, C4, 0C, 89, 45, DC, FF...
 
[+]

Entropy:
6.2080

Code size:
373 KB (381,952 bytes)

Service
Display name:
MirageWorks2 Watchdog Service

Service name:
NWSVC.mworks2

Type:
Win32OwnProcess


Scan nwsvc.exe - Powered by Reason Core Security