spappsv64.dll

1.0.3.418

Thinknice Co. Limited

The module spappsv64.dll by Thinknice Co. Limited has been detected as adware by 7 anti-malware scanners. This file is typically installed with the program SupTab by Thinknice Co. Limited which is a potentially unwanted software program.
Publisher:
Skytech Co., Ltd.  (signed by Thinknice Co. Limited)

Product:
1.0.3.418

Description:
Skytech

Version:
1.0.3.418

MD5:
996d84fa4b4e45ae275ca46c54789329

SHA-1:
7a5dee7799adcaba410c536555d47bbc2fcf53de

SHA-256:
57ed368c72c0514678cec4ec837c95892690a665a4aa9f6b84ac196add35e2fd

Scanner detections:
7 / 68

Status:
Adware

Analysis date:
4/19/2024 2:13:13 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Agent
4.0.3.14625

G Data
Win64.Application.SubTab
14.6.24

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3658

Malwarebytes
PUP.Optional.Skytech.A
v2014.06.25.11

Qihoo 360 Security
Malware.Radar03.Gen
1.0.0.1015

Reason Heuristics
PUP.ThinkniceCoLimited.J
14.6.25.11

Sophos
Elex
4.98

File size:
532.1 KB (544,880 bytes)

Product version:
1.0.3.418

Copyright:
Skytech Copyright (C) 2014

Original file name:
SProtect.dll

File type:
Dynamic link library (Win64 DLL)

Language:
Chinese (Simplified, China)

Common path:
C:\Program Files\suptab\spappsv64.dll

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/26/2013 7:34:13 AM

Valid to:
11/27/2014 7:34:13 AM

Subject:
CN=Thinknice Co. Limited, O=Thinknice Co. Limited, L=HongKong, S=HongKong, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11218A5EF69A65044FE28125681D829B5EFE

File PE Metadata
Compilation timestamp:
6/17/2014 10:00:50 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:JnLgaMkbg7hasztn4TD/Tchw1cQTTguAL59Gry5Qh/gftpSlLn:C7hasz0371Kke5QB+2R

Entry address:
0x234BC

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, 2B, 8E, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, 03, 00, 00, 00, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 20, 4C, 89, 40, 18, 89, 50, 10, 48, 89, 48, 08, 56, 57, 41, 56, 48, 83, EC, 50, 49, 8B, F0, 8B, DA, 4C, 8B, F1, BA, 01, 00, 00, 00, 89, 50, B8, 85, DB, 75, 0F, 39, 1D, 88, C9, 05, 00, 75, 07, 33, C0, E9, D2, 00, 00, 00, 8D, 43, FF...
 
[+]

Entropy:
4.8756

Code size:
241.5 KB (247,296 bytes)

The file spappsv64.dll has been discovered within the following program.

SupTab  by Thinknice Co. Limited
SupTab is an web browser advertisement injection extension that is designed with the core purpose of delivering ads to the user's web browser. Ads are in the form of banners (both static and videos) as well as context-hyper links.
80% remove it
 
Powered by Should I Remove It?

Remove spappsv64.dll - Powered by Reason Core Security