IDProtect Monitor.exe

IDProtect Client

Athena Smartcard Solutions

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘IDProtect Monitor’.
Publisher:
Athena Smartcard Solutions  (signed and verified)

Product:
IDProtect Client

Description:
IDProtect Monitor

Version:
6, 0, 0, 6

MD5:
06f7daece26d670a2a2ccc37ade88b1c

SHA-1:
ea6d0ffeaaf0e02eba10f1e5269718df727f6827

SHA-256:
a6a83e959cbd610b5daafb3556ea62d50c0d71236e8cfa3fcad2fcb2ab8436a7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 5:08:17 PM UTC  (today)

File size:
494.3 KB (506,168 bytes)

Product version:
6, 0, 0, 6

Copyright:
Athena-scs (c). All rights reserved.

Original file name:
IDProtect Monitor.exe

File type:
Executable application (Win32 EXE)

Language:
Spanish (Argentina)

Common path:
C:\Program Files\athena\idprotect client\utils\idprotect monitor.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/19/2011 9:00:00 PM

Valid to:
6/14/2014 8:59:59 PM

Subject:
CN=Athena Smartcard Solutions, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Athena Smartcard Solutions, L=Herzliya, S=Herzliya, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
609E196198995E40E7C6ABB55256172B

File PE Metadata
Compilation timestamp:
7/29/2013 7:17:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:imbHmI0Lz8JlLO6nCSj6ekuCsfCklP6Cz/8Ebli9TeJSi/n/IyIFoUWixxa/Mpq:9zb0cLPPjlku1Xi6JSiP/RiK

Entry address:
0x372AB

Entry point:
E8, 64, AA, 00, 00, E9, 17, FE, FF, FF, 8B, 4C, 24, 04, 53, 33, DB, 3B, CB, 56, 57, 74, 08, 8B, 7C, 24, 14, 3B, FB, 77, 1B, E8, 43, 0F, 00, 00, 6A, 16, 5E, 89, 30, 53, 53, 53, 53, 53, E8, 1F, E9, FF, FF, 83, C4, 14, 8B, C6, EB, 31, 8B, 74, 24, 18, 3B, F3, 75, 04, 88, 19, EB, D9, 8B, D1, 8A, 06, 88, 02, 42, 46, 3A, C3, 74, 03, 4F, 75, F3, 3B, FB, 75, 10, 88, 19, E8, 07, 0F, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, C0, 33, C0, 5F, 5E, 5B, C3, 6A, 14, 68, E0, EC, 45, 00, E8, DE, 56, 00, 00, 83, 65, FC, 00, FF...
 
[+]

Code size:
332 KB (339,968 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
IDProtect Monitor

Command:
"C:\Program Files\athena\idprotect client\utils\idprotect monitor.exe"


Scan IDProtect Monitor.exe - Powered by Reason Core Security