monitor.exe

BACK Monitor Application

Sunplus Innovation Technology Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Lenovo EasyCamera_Monitor’.
Publisher:
Sunplus Innovation Technology Inc.  (signed and verified)

Product:
BACK Monitor Application

Version:
2, 3, 1, 0

MD5:
00bac7ad5b867f71419606620097fca7

SHA-1:
00082b35d44f56f5a7ce4543b46d180825fa29e1

SHA-256:
8ac6dd01df9e8896aa36088d7b26ce6c75ec1b5b203d911d19eb46cb9a6ab241

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 4:11:10 PM UTC  (today)

File size:
251.2 KB (257,224 bytes)

Product version:
2, 3, 1, 0

Copyright:
CopyRight (C) 2009

Original file name:
BACK.EXE

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, China)

Common path:
C:\Program Files\lenovo easycamera\monitor.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/13/2009 5:30:00 AM

Valid to:
11/14/2010 5:29:59 AM

Subject:
CN=Sunplus Innovation Technology Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sunplus Innovation Technology Inc., L=Hsinchu, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2928081DF4F71970C909C570EDD4AF5D

File PE Metadata
Compilation timestamp:
8/24/2010 7:02:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:FAbCtgIO4WBvgPAHqGK8GYDl02UUbE49K:y4WOIfju2UvIK

Entry address:
0x18AD1

Entry point:
E8, CD, 69, 00, 00, E9, 16, FE, FF, FF, 6A, 00, FF, 74, 24, 14, FF, 74, 24, 14, FF, 74, 24, 14, FF, 74, 24, 14, E8, 45, 6A, 00, 00, 83, C4, 14, C3, 8B, 44, 24, 04, 66, 8B, 08, 40, 40, 66, 85, C9, 75, F6, 2B, 44, 24, 04, D1, F8, 48, C3, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04...
 
[+]

Entropy:
6.0490

Code size:
164 KB (167,936 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Lenovo EasyCamera_Monitor

Command:
C:\Program Files\lenovo easycamera\monitor.exe


Scan monitor.exe - Powered by Reason Core Security