alsvc.exe

SKL Client

Deep Software Inc.

It runs as a separate (within the context of its own process) windows Service named “Salsvc”.
Publisher:
Deep Software Inc.  (signed and verified)

Product:
SKL Client

Version:
5.0.2.835

MD5:
fabf97a29a48b96e97a49168eeef27dd

SHA-1:
86c71c1b85bf4e60663129ed7ef8136ab2bbe134

SHA-256:
c50f9e58dc3f4fbeb632e89eb51f4b2e0fdeae56ccb5e72f64c65b6e2c7f1a33

Scanner detections:
6 / 68

Status:
Clean  (6 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/19/2024 9:49:26 PM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
UnclassifiedMalware
23487

McAfee
Program.Keylog-ActivityKey
5600.6504

Quick Heal
Spyware.Keylogger (Not a Virus)
1.16.11.00

Trend Micro House Call
SPYW_KEYLOG
7.2.30

Trend Micro
SPYW_KEYLOG
10.465.30

VIPRE Antivirus
Activity Monitor
10749

File size:
781.9 KB (800,680 bytes)

Product version:
5.0.2.835

Copyright:
Copyright © 2000-2011 Deep Software Inc.

File type:
Executable application (Win32 EXE)

Language:
English (Canada)

Common path:
C:\ProgramData\{b3670a23-3813-470e-a99a-2bd9c5b97d38}\alsvc.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/20/2010 10:00:00 PM

Valid to:
2/11/2013 9:59:59 PM

Subject:
CN=Deep Software Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Deep Software Inc., L=New Westminster, S=British Columbia, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3D1CB78AFC8D91BE032120FB59844936

File PE Metadata
Compilation timestamp:
5/4/2011 8:00:45 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
24576:+u1CxRezHO1jTTkMSOD1aNtZS1Ti2INnQ:BAxTxwNtZS1G2UnQ

Entry address:
0x1000

Entry point:
68, 01, 70, 57, 00, E8, 01, 00, 00, 00, C3, C3, A5, 2D, D5, 64, FA, 42, 81, EA, 2A, DB, 91, 0F, BC, 9A, 04, 33, B7, 9A, A6, 03, B4, 60, 0E, 1F, D5, 07, CF, 83, 29, 49, 12, DF, 85, 05, C6, 01, 4D, AA, EF, 90, 9A, 68, CE, 7A, 15, 77, D1, 84, 12, DA, 54, 1B, B8, F3, BB, C0, B1, E0, BD, 94, 94, C2, BD, F1, 97, 3E, 4E, 27, 4A, D2, 5A, 3D, 65, FF, B6, 34, 09, 9D, 6A, A6, B3, BC, 49, 37, 19, BF, 65, EC, 9A, 10, DF, 60, 1F, AE, 24, FA, 60, DD, 48, D5, 24, E8, 7C, 2D, E5, 98, 00, 20, EF, F0, BF, 3F, 67, 0D, 41, E9...
 
[+]

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
812.5 KB (832,000 bytes)

Service
Display name:
Salsvc

Description:
SoftActivity KL Client Service

Type:
Win32OwnProcess


Scan alsvc.exe - Powered by Reason Core Security