Extramon.exe

Extramon

KaVoom Software Inc.

It runs as a separate (within the context of its own process) windows Service named “Extramon”.
Publisher:
KaVoom Software Inc.  (signed and verified)

Product:
Extramon

Version:
3, 38, 0, 0

MD5:
605837ebbee0b2ebfba6f5f23dbbec03

SHA-1:
e5436676eb7f979b4dccccd90ddcaee830bfaffc

SHA-256:
44b6c3bd2a119745bfcf775e086926325e50979ad77426d23118a4c45e6804cd

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/15/2025 3:16:11 AM UTC  (today)

File size:
4 MB (4,205,672 bytes)

Product version:
3, 38, 0, 0

Copyright:
Copyright (C) 2011

Original file name:
Extramon.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\common files\extramon\x64\extramon.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
11/4/2010 8:00:00 PM

Valid to:
1/22/2012 6:59:59 PM

Subject:
CN=KaVoom Software Inc., O=KaVoom Software Inc., L=Vancouver, S=BC, C=CA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
434C2D07375ED1BAAFAD0C44C3D5B638

File PE Metadata
Compilation timestamp:
3/14/2011 8:01:51 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:YNdfSaeQjiNfONND/ZhSejVfhwwp4hdHpafpMS6SaFBujkeW1kJ4:esONgeJYpSa9uIXa4

Entry address:
0x18BC80

Entry point:
48, 83, EC, 28, E8, C7, B7, 00, 00, 48, 83, C4, 28, E9, 0E, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 48, 89, 0D, 31, 09, 21, 00, C3, CC, CC, CC, CC, CC, CC, CC, CC, 40, 53, 48, 81, EC, A0, 05, 00, 00, 48, 8D, 8C, 24, D0, 00, 00, 00, FF, 15, D9, 16, 0E, 00, 48, 8D, 4C, 24, 30, 33, D2, 41, B8, 98, 00, 00, 00, E8, 97, 28, 00, 00, 48, 8B, 84, 24, A8, 05, 00, 00, C7, 44, 24, 30, 0D, 00, 00, C0, 48, 89, 44, 24, 40, 48, 8D, 44, 24, 30, 48, 89, 44, 24, 20, 48, 8D, 84, 24, D0, 00, 00, 00...
 
[+]

Code size:
2.4 MB (2,538,496 bytes)

Service
Display name:
Extramon

Type:
Win32OwnProcess


Scan Extramon.exe - Powered by Reason Core Security