AspEncrypt.dll

AspEncrypt Active Server Component

Persits Software, Inc.

The library AspEncrypt.dll, “AspEncrypt 2.2.0.2” has been detected as malware by 7 anti-virus scanners.
Publisher:
Persits Software, Inc.  (signed and verified)

Product:
AspEncrypt Active Server Component

Description:
AspEncrypt 2.2.0.2

Version:
2, 2, 0, 2

MD5:
6b6015258088d3a7c81fa0914c6aa773

SHA-1:
192b86edb80334e928d0c320235ae06ba6175555

SHA-256:
cc68a1069a134eb8d22103fa4cb3635cc51c07a81ebc1d7efe9b08b6b0b6e342

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
5/6/2024 10:03:25 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2080126
691

Bitdefender
Trojan.GenericKD.2080126
1.0.20.370

Emsisoft Anti-Malware
Trojan.GenericKD.2080126
8.15.03.15.05

F-Secure
Trojan.GenericKD.2080126
11.2015-15-03_1

G Data
Trojan.GenericKD.2080126
15.3.24

MicroWorld eScan
Trojan.GenericKD.2080126
16.0.0.222

nProtect
Trojan.GenericKD.2080126
15.01.15.01

File size:
204.8 KB (209,744 bytes)

Product version:
2, 2, 0, 2

Copyright:
Copyright (c) 1999 - 2003 Persits Software, Inc.

Original file name:
AspEncrypt.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Windows\System32\aspencrypt.dll

Digital Signature
Authority:
Thawte Consulting cc

Valid from:
8/6/2003 9:32:35 PM

Valid to:
8/21/2004 11:05:04 AM

Subject:
CN="Persits Software, Inc.", OU=Secure Application Development, O="Persits Software, Inc.", L=Arlington, S=Virginia, C=US

Issuer:
E=server-certs@thawte.com, CN=Thawte Server CA, OU=Certification Services Division, O=Thawte Consulting cc, L=Cape Town, S=Western Cape, C=ZA

Serial number:
1ED7F6

Registration
CLSIDs:
{B72DF070-28A4-11D3-BF19-009027438003}, {F9463571-87CB-4A90-A1AC-2284B7F5AF4E}

ProgIDs:
Persits.CryptoManager.1, Persits.XEncrypt.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
12/20/2003 8:50:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:RGe+ktyeM/IP1q4aBEHHLmuxT2DsT/BjHgJXoYURJ6:0e+5gxLyg7tmfg6

Entry address:
0x14125

Entry point:
55, 8B, EC, 53, 8B, 5D, 08, 56, 8B, 75, 0C, 57, 8B, 7D, 10, 85, F6, 75, 09, 83, 3D, 78, 75, 02, 10, 00, EB, 26, 83, FE, 01, 74, 05, 83, FE, 02, 75, 22, A1, C4, 8C, 02, 10, 85, C0, 74, 09, 57, 56, 53, FF, D0, 85, C0, 74, 0C, 57, 56, 53, E8, E7, FE, FF, FF, 85, C0, 75, 04, 33, C0, EB, 4E, 57, 56, 53, E8, CC, 4E, FF, FF, 83, FE, 01, 89, 45, 0C, 75, 0C, 85, C0, 75, 37, 57, 50, 53, E8, C3, FE, FF, FF, 85, F6, 74, 05, 83, FE, 03, 75, 26, 57, 56, 53, E8, B2, FE, FF, FF, 85, C0, 75, 03, 21, 45, 0C, 83, 7D, 0C, 00...
 
[+]

Entropy:
5.9922

Developed / compiled with:
Microsoft Visual C++

Code size:
116 KB (118,784 bytes)

Remove AspEncrypt.dll - Powered by Reason Core Security