spsaner.exe

SecPod Saner

SecPod Technologies Private Limited

It runs as a scheduled task under the Windows Task Scheduler named saner triggered to execute each time a user logs in. This is installed with SecPod Saner.
Publisher:
SecPod Technologies Pvt. Ltd.  (signed by SecPod Technologies Private Limited)

Product:
SecPod® Saner

Version:
1.1.0.0

MD5:
a504e218db24a49fd184b496e8a701f5

SHA-1:
3aefee9f0479fbc7dd46a22c757eefdead4d8c1d

SHA-256:
8671da9e7e1969870cd573fa35596af44957b27c45a8a9f7233af1ea5111b32e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 5:15:26 AM UTC  (today)

File size:
1.3 MB (1,359,200 bytes)

Product version:
1.1.0.0

Copyright:
Copyright© SecPod Technologies 2014

Original file name:
spsaner.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\secpod saner\spsaner.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
8/16/2013 8:32:59 AM

Valid to:
8/16/2014 3:48:29 AM

Subject:
CN=SecPod Technologies Private Limited, O=SecPod Technologies Private Limited, L=Bangalore, S=KARNATAKA, C=IN

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4EC8066DCB7068

File PE Metadata
Compilation timestamp:
6/4/2014 4:32:43 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:t6INxXecv0GSNMwW7dCeMZgDvSa8/lIrhoKro90Oht5ZKetQxwZiv6TylNzeXGPB:RHHTyW7dCefl030K8Nb

Entry address:
0x5EA19

Entry point:
E8, A5, 04, 00, 00, E9, 63, FD, FF, FF, 6A, 14, 68, 38, 29, 52, 00, E8, D1, 01, 00, 00, 83, 65, FC, 00, FF, 4D, 10, 78, 3A, 8B, 4D, 08, 2B, 4D, 0C, 89, 4D, 08, FF, 55, 14, EB, ED, 8B, 45, EC, 89, 45, E4, 8B, 45, E4, 8B, 00, 89, 45, E0, 8B, 45, E0, 81, 38, 63, 73, 6D, E0, 74, 0B, C7, 45, DC, 00, 00, 00, 00, 8B, 45, DC, C3, E8, EF, 04, 00, 00, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, C7, 01, 00, 00, C2, 10, 00, 6A, 0C, 68, 58, 29, 52, 00, E8, 73, 01, 00, 00, 83, 65, E4, 00, 8B, 75, 0C, 8B, C6, 0F, AF, 45...
 
[+]

Entropy:
7.3804

Packer / compiler:
PEQuake V0.06

Code size:
419 KB (429,056 bytes)

Scheduled Task
Task name:
saner

Trigger:
Logon (Runs on logon)

Action:
spsaner.exe hide


The file spsaner.exe has been discovered within the following program.

SecPod Saner  by SecPod Technologies Pvt Ltd
About 9% of users remove it
 
Powered by Should I Remove It?

Scan spsaner.exe - Powered by Reason Core Security