spnsrvnt.exe

SPI

SafeNet, Inc.

The executable spnsrvnt.exe, “Sentinel Protection Server for SuperPro and UltraPro network keys” has been detected as malware by 3 anti-virus scanners. It runs as a windows Service named “Sentinel Protection Server”.
Publisher:
SafeNet, Inc  (signed by SafeNet, Inc.)

Product:
SPI

Description:
Sentinel Protection Server for SuperPro and UltraPro network keys

Version:
7, 4, 0, 0

MD5:
4e452aba3960fd00948b6fdfc8e25856

SHA-1:
4f6fc0b57ae70df2960765f12501c6ea410ba160

SHA-256:
5345709f03066ce6bb9d4ebe7c293b7212be5101bfacf7a3e434923c370198cb

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
11/15/2024 5:26:08 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.15.154

File size:
278 KB (284,679 bytes)

Product version:
7, 4, 0, 0

Copyright:
Copyright © 2007 SafeNet, Inc

Trademarks:
Sentinel® is a registered trademark of SafeNet, Inc. Windows(TM) is a trademark of Microsoft Corporation

Original file name:
spnsrvnt.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\common files\safenet sentinel\sentinel protection server\winnt\spnsrvnt.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/13/2007 8:00:00 AM

Valid to:
3/14/2008 7:59:59 AM

Subject:
CN="SafeNet, Inc.", OU=Enterprise Security Division, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="SafeNet, Inc.", L=Baltimore, S=Maryland, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4D1EEDD778A51A3D59D419A8B06CA09C

File PE Metadata
Compilation timestamp:
4/27/2007 2:47:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

Entry address:
0x20C8C

Entry point:
E9, 6A, 59, 00, 00, 68, 30, A7, 42, 00, 68, 08, 05, 42, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 10, 53, 56, 57, 89, 65, E8, FF, 15, EC, A0, 42, 00, 33, D2, 8A, D4, 89, 15, 00, 18, 43, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, FC, 17, 43, 00, C1, E1, 08, 03, CA, 89, 0D, F8, 17, 43, 00, C1, E8, 10, A3, F4, 17, 43, 00, 6A, 01, E8, CB, 12, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, AB, 00, 00, 00, 59, E8, D3, 1E, 00, 00, 85, C0, 75, 08, 6A, 10, E8, 9A, 00, 00, 00, 59, 83, 65, FC, 00...
 
[+]

Entropy:
7.0524

Packer / compiler:
Xtreme-Protector v1.05

Code size:
164 KB (167,936 bytes)

Service
Display name:
Sentinel Protection Server

Service name:
SentinelProtectionServer

Description:
Manages Sentinel SuperPro and UltraPro keys attached to this computer.

Type:
Win32OwnProcess, InteractiveProcess


Remove spnsrvnt.exe - Powered by Reason Core Security