SppClient.exe

Specops Password Client

Specops Software Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Specops Password Client’.
Publisher:
Specops Software  (signed by Specops Software Inc.)

Product:
Specops Password Client

Version:
6,0,20604,1

MD5:
d035b2c6f79b139883c1d9cd220ae523

SHA-1:
db0e2bed0162cbde3741aab8bb151c2d9e897a7c

SHA-256:
3b2082c6540fd6b634d303206db6283f0a039888dc9f3739c92de3a4bc7aaf37

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 10:05:25 PM UTC  (today)

File size:
853.4 KB (873,872 bytes)

Product version:
6,0,20604,1

Copyright:
Copyright © Specops Software

Original file name:
SppClient.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Windows\System32\sppclient.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
1/26/2011 2:00:00 AM

Valid to:
1/26/2013 1:59:59 AM

Subject:
CN=Specops Software Inc., O=Specops Software Inc., L=Toronto, S=Ontario, C=CA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
45620ABF0327F991350E156FA38A11AB

File PE Metadata
Compilation timestamp:
6/4/2012 10:51:15 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:4xo0/57YcySaSfKvt9UhqyOEXAIns21di05Cmt6IVIvtIrZxptGkng8qwm0zPInR:4xoIh1LffKrUjOpIn9di04+Hg8NrzqMO

Entry address:
0x1065B

Entry point:
E8, CE, 48, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 8B, 4D, 08, 53, 33, D2, 56, 57, 89, 55, FC, 3B, CA, 0F, 84, 85, 00, 00, 00, 8B, 7D, 0C, 3B, FA, 75, 07, 39, 55, 10, 75, 79, EB, 05, 39, 55, 10, 74, 72, 39, 55, 14, 75, 07, 39, 55, 18, 75, 68, EB, 05, 39, 55, 18, 74, 61, 39, 55, 1C, 75, 07, 39, 55, 20, 75, 57, EB, 05, 39, 55, 20, 74, 50, 39, 55, 24, 75, 46, 39, 55, 28, 75, 46, 33, C0, 40, 8B, F1, 66, 39, 16, 74, 08, 48, 83, C6, 02, 3B, C2, 77, F3, 66, 83, 3E, 3A, 75, 3A, 3B, FA, 74, 1B, 83, 7D...
 
[+]

Entropy:
3.5147

Code size:
122.5 KB (125,440 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Specops Password Client

Command:
C:\Windows\System32\sppclient.exe


Scan SppClient.exe - Powered by Reason Core Security