LinkScannerMonitor.exe

LinkScanner

Exploit Prevention Labs, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘LinkScanner Monitor’. This is installed with LinkScanner.
Publisher:
Exploit Prevention Labs, Inc.  (signed and verified)

Product:
LinkScanner

Description:
LinkScanner Monitor

Version:
2.7.0.105

MD5:
997dab4bf2d362f2f7528a22112ce76d

SHA-1:
9e0ebfed4f02fab4dbd73ab9edfa5df787673a0a

SHA-256:
9830cdd5c4df8b82072c17f9debdd42740c76d0d6c0a4fdb440fd7dd2a5a08ba

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 10:38:12 AM UTC  (today)

File size:
1.9 MB (1,967,384 bytes)

Product version:
2.7.0.105

Copyright:
Copyright (C) 2006-2007 Exploit Prevention Labs, Inc. All rights reserved.

Trademarks:
LinkScanner, SocketShield, Exploit Prevention Labs

Original file name:
LinkScannerMonitor.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\explabs.com\linkscanner\linkscannermonitor.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/11/2006 12:00:00 AM

Valid to:
3/10/2008 11:59:59 PM

Subject:
CN="Exploit Prevention Labs, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Exploit Prevention Labs, Inc.", L=Carlisle, S=Pennsylvania, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3B8B0513F10888BFF0CA59975B802A7A

File PE Metadata
Compilation timestamp:
11/25/2007 4:26:55 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:OCuKdD+e4c3QM2axSiniTekn2WLrOXuAF+aJ8qdsw91C/ILcY1TseQIqu1W18NLP:OCuhe4c3X2CiTc7EfY1TWIqufP

Entry address:
0x4B639

Entry point:
E8, 0C, BC, 00, 00, E9, 16, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 08, 57, 53, 56, 8A, 11, 8B, 7C, 24, 10, 84, D2, 74, 6F, 8A, 71, 01, 84, F6, 74, 55, 8B, F7, 8B, 4C, 24, 14, 8A, 07, 83, C6, 01, 3A, C2, 74, 17, 84, C0, 74, 0D, 8A, 06, 83, C6, 01, 3A, C2, 74, 0A, 84, C0, 75, F3, 5E, 5B, 5F, 33, C0, C3, 8A, 06, 83, C6, 01, 3A, C6, 75, E9, 8D, 7E, FF, 8A, 61, 02, 84, E4, 74, 28, 8A, 06, 83, C6, 02, 3A, C4, 75, BE, 8A, 41, 03, 84, C0, 74, 18, 8A, 66, FF, 83, C1, 02, 3A, C4...
 
[+]

Entropy:
6.3509

Code size:
1012 KB (1,036,288 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
LinkScanner Monitor

Command:
C:\Program Files\explabs.com\linkscanner\linkscannermonitor.exe \auto


The file LinkScannerMonitor.exe has been discovered within the following program.

LinkScanner  by Exploit Prevention Labs, Inc.
About 5% of users remove it
 
Powered by Should I Remove It?

Scan LinkScannerMonitor.exe - Powered by Reason Core Security