secsvr.exe

Kakasoft Software Co. Ltd.

The executable secsvr.exe has been detected as malware by 7 anti-virus scanners.
Publisher:
Kakasoft Software Co. Ltd.  (signed and verified)

MD5:
43f4de0796f1640c7fcbf5b076fd4878

SHA-1:
4ebdc85073af345eea1dfdd541035877c3304ab2

SHA-256:
225752c3ab3979566e089feca70281c47d1bb045c4188cd886e6a091dc495347

Scanner detections:
7 / 68

Status:
Malware

Explanation:
The software cotains keystroke monitoring/logging capablities which may or may not be installed without the user's knowledge.

Analysis date:
4/26/2024 11:17:44 AM UTC  (today)

Scan engine
Detection
Engine version

Bitdefender
Application.Keylogger.QJN
1.0.20.30

Comodo Security
UnclassifiedMalware
16955

Emsisoft Anti-Malware
Application.Keylogger.QJN
8.16.01.06.12

ESET NOD32
Win32/KeyLogger.AnyKeylogger (variant)
10.8811

F-Secure
Application.Keylogger.QJN
11.2016-06-01_4

G Data
Application.Keylogger.QJN
16.1.22

MicroWorld eScan
Application.Keylogger.QJN
17.0.0.18

File size:
5 MB (5,273,112 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\common files\akl\secsvr.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/11/2012 7:00:00 AM

Valid to:
12/12/2013 6:59:59 AM

Subject:
CN=Kakasoft Software Co. Ltd., OU=Technical department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Kakasoft Software Co. Ltd., L=shenzhen, S=guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
26E6AF3C3910B77FF10FEB6186D4E032

File PE Metadata
Compilation timestamp:
8/30/2013 1:44:25 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:lnrUhhMPHrLWyZAZVhgFSAYUSxNotb+j9WYVf0r:95XzgCaYYWr

Entry address:
0x37B140

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, 34, E7, 76, 00, E8, 23, 09, C9, FF, 68, 08, B2, 77, 00, 6A, 00, 6A, 00, E8, 89, 1D, C9, FF, 8B, D8, E8, FA, 1E, C9, FF, 3D, B7, 00, 00, 00, 75, 2F, 6A, 00, 68, 20, B2, 77, 00, E8, 43, 27, C9, FF, 85, C0, 74, 17, 6A, 00, 6A, 00, 68, 09, 14, 00, 00, 50, E8, 28, 2A, C9, FF, 53, E8, D2, 20, C9, FF, EB, 6C, 53, E8, CA, 20, C9, FF, EB, 64, A1, 38, F9, 78, 00, 8B, 00, E8, 9C, EF, D7, FF, A1, 38, F9, 78, 00, 8B, 00, B2, 01, E8, CA, 0C, D8, FF, 8B, 0D, 68, F3, 78, 00, A1, 38, F9, 78...
 
[+]

Entropy:
6.8988

Developed / compiled with:
Microsoft Visual C++

Code size:
3.5 MB (3,645,952 bytes)

Remove secsvr.exe - Powered by Reason Core Security