spidergate.exe

Dr.Web

Doctor Web Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SpIDerGate’.
Publisher:
Doctor Web, Ltd.  (signed by Doctor Web Ltd.)

Product:
Dr.Web ®

Description:
SpIDer Gate ® for Windows

Version:
6.0.0.02240

MD5:
3f3373a3c53eca4fb5df18151c39ab11

SHA-1:
41e934ef776d2590b4fac8bee9dc33225c62ed64

SHA-256:
9a757d52050a3e97f0b94d932a38857915b0ba55465ccbabe210bf65f397b03c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 6:57:40 PM UTC  (today)

File size:
1.8 MB (1,854,192 bytes)

Product version:
6.0.0.02240

Copyright:
Copyright © Doctor Web, Ltd., 1992-2010

Original file name:
spidergate.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\drweb\spidergate.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/8/2008 3:00:00 AM

Valid to:
10/8/2011 2:59:59 AM

Subject:
CN=Doctor Web Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Doctor Web Ltd., S=Saint-Petersburg, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0D34695F3DF1206DA6579A0DB785C25F

File PE Metadata
Compilation timestamp:
2/24/2010 4:49:08 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:Xzeam5MADCuD/YBR5AB0UJUR21WqrsAF7TkLJl3cQ8vULLkrFWSqn9lzn1+GY6/:yfDQz5ANJdW67T2Jl3cQ0U7z1+u/

Entry address:
0x110940

Entry point:
51, E8, C5, 3B, FB, FF, 68, 20, 09, 51, 00, FF, 15, 50, 11, 54, 00, 68, 20, F3, 54, 00, FF, 15, 48, 11, 54, 00, 85, C0, 74, 29, 68, 3C, F3, 54, 00, 50, FF, 15, 28, 11, 54, 00, 85, C0, 74, 19, 8D, 0C, 24, 51, 6A, 05, 68, 9C, 17, 55, 00, 50, FF, 15, 3C, 11, 54, 00, 50, FF, 15, 4C, 11, 54, 00, 83, C4, 04, E9, FD, 3D, FB, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 06, 83, F8, FF, 74, 0C, 50, E8, 13, 98, FE, FF, C7, 06, FF, FF, FF, FF, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC...
 
[+]

Code size:
1.2 MB (1,308,160 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SpIDerGate

Command:
"C:\Program Files\drweb\spidergate.exe" -autorun


Scan spidergate.exe - Powered by Reason Core Security