cnwida.exe

imagePROGRAF Status Monitor

Canon Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘CnwiDeviceAgent’.
Publisher:
Canon Inc.  (signed and verified)

Product:
imagePROGRAF Status Monitor

Description:
imagePROGRAF Status Monitor for x64 Edition

Version:
3.8.0.0

MD5:
3febb12cac065d4150ad9fabdbf90d41

SHA-1:
b4c35f8808c8064bf672245ff3aa7b971e52135a

SHA-256:
eda6c85c0c310fdb0d0b154b5c8ab17fd25c7c7c81e007ba26b9c9c7ecbd12ac

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 10:48:46 PM UTC  (today)

File size:
65.8 KB (67,344 bytes)

Product version:
3.80

Copyright:
Copyright CANON INC. 2002-2008. All rights reserved.

Original file name:
cnwida.exe

File type:
Executable application (Win64 EXE)

Language:
Japonski (Japonia)

Common path:
C:\Program Files\canon\imageprografstatusmonitor\cnwida.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/22/2008 1:00:00 AM

Valid to:
1/22/2009 12:59:59 AM

Subject:
CN=Canon Inc., OU=L Printer Products, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Canon Inc., L=Kawasaki, S=Kanagawa, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
21EED3AC398FC0803084CEC2D64F5374

File PE Metadata
Compilation timestamp:
6/23/2008 6:29:43 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
768:ZDDa5rlpt0UpknVpXY3ke3e76xvliLGuzJUxY0PP4ERaSuiXT9F/H/rLWb:ZD2zmQk8kd76O9Uy0PP4iaS9Tn/frC

Entry address:
0x1F60

Entry point:
48, 8B, C4, 48, 81, EC, A8, 00, 00, 00, 48, 89, 58, 18, 48, 89, 78, 20, 48, 8D, 48, 88, FF, 15, 84, 81, 00, 00, 90, FF, 15, 75, 81, 00, 00, 48, 8B, C8, 33, D2, 41, B8, 94, 00, 00, 00, FF, 15, 5C, 81, 00, 00, 48, 8B, D8, 48, 85, C0, 75, 0A, B8, FF, 00, 00, 00, E9, 62, 02, 00, 00, C7, 00, 94, 00, 00, 00, 48, 8B, C8, FF, 15, 33, 81, 00, 00, 85, C0, 75, 1E, FF, 15, 39, 81, 00, 00, 48, 8B, C8, 4C, 8B, C3, 33, D2, FF, 15, 13, 81, 00, 00, B8, FF, 00, 00, 00, E9, 31, 02, 00, 00, 8B, 43, 10, 89, 05, 44, E2, 00, 00...
 
[+]

Code size:
35 KB (35,840 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
CnwiDeviceAgent

Command:
C:\Program Files\canon\imageprografstatusmonitor\cnwida.exe