SFAgent.exe

Sayonara Meiwaku Mail

SPAMfighter ApS

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SPAMfighter Agent’.
Publisher:
SPAMfighter ApS  (signed and verified)

Product:
Sayonara Meiwaku Mail

Description:
Sayonara Meiwaku Mail Agent

Version:
6, 4, 29, 0

MD5:
e5b0598e4097b3116b608a72adb4f1ad

SHA-1:
eb1e0793680a2bbf44843918e057b5b56a708f7a

SHA-256:
776cb02cbd64825122680450a1b6f076683d2fa39161d60af5d18e2150942c6b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 8:10:07 AM UTC  (today)

File size:
321.1 KB (328,840 bytes)

Product version:
6, 4, 29, 0

Copyright:
Copyright (C) 2003, 2009 SPAMfighter ApS

Original file name:
SFAgent.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\sayonara meiwaku mail\sfagent.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
4/21/2008 9:00:00 AM

Valid to:
4/22/2010 8:59:59 AM

Subject:
CN=SPAMfighter ApS, OU=Application Development, O=SPAMfighter ApS, L=Copenhagen, S=Denmark, C=DK

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
41E54BBE25DF3D30BD273C27AF79D3C3

File PE Metadata
Compilation timestamp:
3/12/2009 6:40:16 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:Z3jxmwws1JrntOuhGz0k8pRwtPUCiFHmxFpK+WAJUtogso:Zzxmwws1FEAX16Utom

Entry address:
0x1D01D

Entry point:
E8, 67, A8, 00, 00, E9, 16, FE, FF, FF, C3, B8, AA, 83, 42, 00, A3, 70, DC, 44, 00, C7, 05, 74, DC, 44, 00, A6, 7A, 42, 00, C7, 05, 78, DC, 44, 00, 64, 7A, 42, 00, C7, 05, 7C, DC, 44, 00, 98, 7A, 42, 00, C7, 05, 80, DC, 44, 00, 0E, 7A, 42, 00, A3, 84, DC, 44, 00, C7, 05, 88, DC, 44, 00, 24, 83, 42, 00, C7, 05, 8C, DC, 44, 00, 24, 7A, 42, 00, C7, 05, 90, DC, 44, 00, 8E, 79, 42, 00, C7, 05, 94, DC, 44, 00, 1D, 79, 42, 00, C3, E8, 9B, FF, FF, FF, E8, BD, B3, 00, 00, 83, 7C, 24, 04, 00, A3, DC, 03, 45, 00, 74...
 
[+]

Entropy:
6.4812

Code size:
239.5 KB (245,248 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SPAMfighter Agent

Command:
"C:\Program Files\sayonara meiwaku mail\sfagent.exe" update delay 60


Scan SFAgent.exe - Powered by Reason Core Security