spyprotector.exe

Spy Protector

Alexander Neuber und Matthias Neuber

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Spy Protector’.
Publisher:
Neuber GbR - www.neuber.com  (signed by Alexander Neuber und Matthias Neuber)

Product:
Spy Protector

Version:
1.0.0.0

MD5:
754656be0fc365e068f48e25822e45ca

SHA-1:
40153c3750f3e4496f7edbfb9993638245b4c12c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/14/2025 5:08:15 AM UTC  (today)

File size:
103.2 KB (105,664 bytes)

Product version:
1.0.0.0

Copyright:
Copyright (c) 2002-2003 www.Anti-Spy.Info

Original file name:
spyprotect.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\spyprotector\spyprotector.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/29/2003 2:00:00 AM

Valid to:
4/15/2004 1:59:59 AM

Subject:
CN=Alexander Neuber und Matthias Neuber, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Alexander Neuber und Matthias Neuber, L=Halle, S=Sachsen-Anhalt, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2001 CA, OU=Terms of use at https://www.verisign.com/rpa (c)01, OU=VeriSign Trust Network, O="VeriSign, Inc."

Serial number:
648DC4FC0A5B6A0D08220E8018C2C661

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
1536:H85qfQ5RV1IroUISV3cHcuRdJdtxfownBrpTz6iZ6pps7vjFnX2UxtiwZAIaH:HuRV1woyV3EcsBPnBrZmiQppQm4ZMH

Entry address:
0xE028

Entry point:
55, 8B, EC, 83, C4, EC, 53, 56, 57, 33, C0, 89, 45, EC, B8, B0, DF, 40, 00, E8, C4, 69, FF, FF, BE, 2C, 09, 41, 00, BF, 48, 09, 41, 00, 33, C0, 55, 68, D8, E1, 40, 00, 64, FF, 30, 64, 89, 20, 6A, 01, E8, 6D, A4, FF, FF, 33, C0, E8, 8A, FC, FF, FF, 6A, 00, 68, E8, E1, 40, 00, E8, 76, 6C, FF, FF, 8B, D8, 85, DB, 74, 4D, 53, E8, 22, 6D, FF, FF, 6A, 18, 6A, 00, 68, 00, 04, 00, 00, 53, E8, DB, 6C, FF, FF, 68, FF, FF, 00, 00, E8, C1, 6C, FF, FF, 6A, 40, 68, E8, E1, 40, 00, 8D, 4D, EC, BA, 00, E2, 40, 00, B8, E6...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
53 KB (54,272 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Spy Protector

Command:
C:\Program Files\spyprotector\spyprotector.exe \autostart


Scan spyprotector.exe - Powered by Reason Core Security