srvany.exe

This is a setup program which is used to install the application. It runs as a separate (within the context of its own process) windows Service named “PromiseCIMOM”. The file has been seen being downloaded from www.electrasoft.com.
MD5:
f03ea3d3a14db51b505b86aba8ed3be2

SHA-1:
63803ee958baa09e34cd97104e45c3a27dbfe05c

SHA-256:
ba051c67d3a9ba33efb02fcf354f4be373dcf7daa636de73bdec84456d76dd27

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 6:58:13 AM UTC  (today)

File size:
15 KB (15,360 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
7/10/1995 7:17:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.60

CTPH (ssdeep):
384:LfOw4QSE3EDhmqYs1z83pG9erjTjEvBYQK5W3:Lax1zspGYrjTjEvBYd

Entry address:
0x22AA

Entry point:
64, A1, 00, 00, 00, 00, 55, 8B, EC, 6A, FF, 68, 18, 11, 00, 01, 68, 98, 23, 00, 01, 50, A1, 3C, 34, 00, 01, 64, 89, 25, 00, 00, 00, 00, 8B, 0D, 34, 10, 00, 01, 83, EC, 1C, 89, 01, 8B, 15, 38, 34, 00, 01, A1, 54, 10, 00, 01, 53, 56, 57, 89, 65, E8, 89, 10, E8, B5, 01, 00, 00, 8D, 55, D8, 8D, 45, DC, FF, 35, 34, 34, 00, 01, 52, 50, 8D, 4D, E0, 51, E8, 98, 01, 00, 00, 83, C4, 10, 68, 04, 10, 00, 01, 68, 00, 10, 00, 01, E8, 80, 01, 00, 00, 83, C4, 08, C7, 45, FC, 00, 00, 00, 00, FF, 75, D8, FF, 75, DC, FF, 75...
 
[+]

Developed / compiled with:
Microsoft Visual C, 2.0

Code size:
6 KB (6,144 bytes)

Service
Display name:
PromiseCIMOM

Type:
Win32OwnProcess


The file srvany.exe has been discovered within the following program.

32bit Fax  by ElectraSoft
Publisher's description - “Send and Receive fax from Single computer or Network. Adds a [Print to fax driver] to your all programs giving you access to all the fax machines in the world making them become your printers. Supports Windows. Seamlessly integrates faxing into your Windows environment.”
www.electrasoft.com/32bf.htm
12% remove it
 
Powered by Should I Remove It?

The file srvany.exe has been seen being distributed by the following URL.

Scan srvany.exe - Powered by Reason Core Security