filetosql.exe

SpectorSoft Corporation

The executable filetosql.exe has been detected as malware by 1 anti-virus scanner.
Publisher:
SpectorSoft Corporation  (signed and verified)

MD5:
51cfaad6f9c8edc7a53dcc4ef6bbfae4

SHA-1:
8768d54e79cf3cf4d82121ff943ec8879323dd56

SHA-256:
569073f30ec7dcfc38c0bcb08a6663afdf693e006c333c4544d20c531af08fd9

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
4/19/2024 5:02:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Keylogger.SpectorSoft.SpectorSoftCorporation.Meta (L)
16.1.5.8

File size:
1.5 MB (1,524,624 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\spectorsoft\spector 360 import utility\filetosql.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/23/2013 8:00:00 PM

Valid to:
5/24/2015 7:59:59 PM

Subject:
CN=SpectorSoft Corporation, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=SpectorSoft Corporation, L=Vero Beach, S=Florida, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
098B8BC74886B43A02979EC31D4F15A2

File PE Metadata
Compilation timestamp:
4/17/2014 8:21:32 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:MeyPMbfqLoXtQwlStsBSZzBWzk92MQmX0H/BjLR6d0zC5rjvIECid1unh9rFYTTm:MX0C8XAWBuz7u9Lgd0zC5Xtd0nfFYThI

Entry address:
0xEC84C

Entry point:
E8, 17, 0D, 00, 00, E9, 1C, FD, FF, FF, FF, 25, 90, A4, 4F, 00, FF, 25, 94, A4, 4F, 00, FF, 25, 98, A4, 4F, 00, FF, 25, 9C, A4, 4F, 00, FF, 25, A0, A4, 4F, 00, FF, 25, A4, A4, 4F, 00, FF, 25, A8, A4, 4F, 00, FF, 25, AC, A4, 4F, 00, FF, 25, B0, A4, 4F, 00, FF, 25, B4, A4, 4F, 00, FF, 25, B8, A4, 4F, 00, FF, 25, BC, A4, 4F, 00, FF, 25, C0, A4, 4F, 00, FF, 25, D4, A3, 4F, 00, FF, 25, C8, A4, 4F, 00, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, EA, F9, FF, FF, 51, 8D, 4C, 24, 08, 2B...
 
[+]

Entropy:
6.3985

Code size:
995 KB (1,018,880 bytes)

Remove filetosql.exe - Powered by Reason Core Security