sptdinst-v162-x86.exe

SCSI Pass Through Direct

Duplex Secure Ltd

The executable sptdinst-v162-x86.exe, “SCSI Pass Through Direct setup” has been detected as malware by 4 anti-virus scanners. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
Duplex Secure Ltd.  (signed by Duplex Secure Ltd)

Product:
SCSI Pass Through Direct

Description:
SCSI Pass Through Direct setup

Version:
1.62.0.0 built by: WinDDK

MD5:
d24f2a554a166c4d0e1ca1ae8c91c768

SHA-1:
122360494cecf4a7ef0004ae75e1711440e5cecf

SHA-256:
9018160f31f0e12244ed839905b73e9b127254512c6731da9b02f581adf0c7f3

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
4/25/2024 10:48:05 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Sality
150101-1

Bkav FE
HW32.Packed
1.3.0.6379

F-Prot
W32/Virut.AI!Generic
4.6.5.141

VIPRE Antivirus
Threat.4150696
37588

File size:
860 KB (880,624 bytes)

Product version:
1.62.0.0

Copyright:
Copyright (C) 2004-2009

Original file name:
sptdinst.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\application data\bureau\extra\indispensables\sptdinst-v162-x86.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/27/2007 2:00:00 AM

Valid to:
8/23/2010 1:59:59 AM

Subject:
CN=Duplex Secure Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Duplex Secure Ltd, S=Nevis, C=KN

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3217B318D8B2B1501B3711EE65205704

File PE Metadata
Compilation timestamp:
10/11/2009 10:54:32 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:2+jKcxcwyVBzZugI/NBz+DB5aI/naRbak:TjzxPyVBNxe+DDVk

Entry address:
0x3C05

Entry point:
E8, 02, 06, 00, 00, E9, 4E, FD, FF, FF, CC, FF, 25, 9C, 03, 4B, 00, FF, 25, 98, 03, 4B, 00, FF, 25, AC, 03, 4B, 00, CC, CC, 68, 70, 3C, 40, 00, 64, A1, 00, 00, 00, 00, 50, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, 8B, 45, F8, 89, 65, E8, 50, 8B, 45, FC, C7, 45, FC, FF, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5E, 5B, C9, 51, C3, FF, 25, 78, 03, 4B, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 3B, 0D, 88, E7, 4A...
 
[+]

Code size:
14.5 KB (14,848 bytes)

Remove sptdinst-v162-x86.exe - Powered by Reason Core Security