SppClient.exe

Specops Password Client

Specops Software Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Specops Password Client’.
Publisher:
Specops Software  (signed by Specops Software Inc.)

Product:
Specops Password Client

Version:
5,0,10526,1

MD5:
aeea7b6cb0807a479c3c8de0ea4b711f

SHA-1:
eb30829503abc2fffdc37ed2a712d350b8088052

SHA-256:
784289b482c7a82322616523e17acf76ac6e3d7a89738413697522ef915a3746

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/25/2024 1:20:31 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Crypt.ZPACK.Gen
7.11.30.172

File size:
845.6 KB (865,880 bytes)

Product version:
5,0,10526,1

Copyright:
Copyright © 2001-2010 Specops Software

Original file name:
SppClient.exe

File type:
Executable application (Win32 EXE)

Language:
Swedish (Sweden)

Common path:
C:\Windows\System32\sppclient.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
1/26/2011 1:00:00 AM

Valid to:
1/26/2013 12:59:59 AM

Subject:
CN=Specops Software Inc., O=Specops Software Inc., L=Toronto, S=Ontario, C=CA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
45620ABF0327F991350E156FA38A11AB

File PE Metadata
Compilation timestamp:
5/26/2011 2:53:36 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:kyCVAwacgChw/7wicoZnSW/nZ1XzBg8Nrzqkz:kyCvaZ/7ZcohSW/nZ1XC8lOs

Entry address:
0xF63B

Entry point:
E8, CE, 48, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 8B, 4D, 08, 53, 33, D2, 56, 57, 89, 55, FC, 3B, CA, 0F, 84, 85, 00, 00, 00, 8B, 7D, 0C, 3B, FA, 75, 07, 39, 55, 10, 75, 79, EB, 05, 39, 55, 10, 74, 72, 39, 55, 14, 75, 07, 39, 55, 18, 75, 68, EB, 05, 39, 55, 18, 74, 61, 39, 55, 1C, 75, 07, 39, 55, 20, 75, 57, EB, 05, 39, 55, 20, 74, 50, 39, 55, 24, 75, 46, 39, 55, 28, 75, 46, 33, C0, 40, 8B, F1, 66, 39, 16, 74, 08, 48, 83, C6, 02, 3B, C2, 77, F3, 66, 83, 3E, 3A, 75, 3A, 3B, FA, 74, 1B, 83, 7D...
 
[+]

Code size:
118 KB (120,832 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Specops Password Client

Command:
C:\Windows\System32\sppclient.exe


Scan SppClient.exe - Powered by Reason Core Security