monitor.exe

BACK Monitor Application

Sunplus Innovation Technology Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘HP HD Webcam [Fixed]_Monitor’.
Publisher:
Sunplus Innovation Technology Inc.  (signed and verified)

Product:
BACK Monitor Application

Version:
2, 3, 1, 4

MD5:
efa59d46f53b6b79ace49a58d3a2e453

SHA-1:
3c1c35338974e84bcf0ea4633b78bef0e2de4ab4

SHA-256:
5104d14f1bf889c8ce004a60a3089a047f3d129d0f80e900edecedcd56d39f92

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 3:29:44 AM UTC  (today)

File size:
259.2 KB (265,416 bytes)

Product version:
2, 3, 1, 4

Copyright:
CopyRight (C) 2010

Original file name:
BACK.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\hp hd webcam [fixed]\monitor.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/13/2009 8:00:00 AM

Valid to:
11/14/2010 7:59:59 AM

Subject:
CN=Sunplus Innovation Technology Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sunplus Innovation Technology Inc., L=Hsinchu, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2928081DF4F71970C909C570EDD4AF5D

File PE Metadata
Compilation timestamp:
11/3/2010 2:20:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:rmkkV9TUI+eLxFqfOsnEGxB43nIIp1xHGB:kUOmfdx4IqmB

Entry address:
0x192C1

Entry point:
E8, 81, 7A, 00, 00, E9, 16, FE, FF, FF, 6A, 00, FF, 74, 24, 14, FF, 74, 24, 14, FF, 74, 24, 14, FF, 74, 24, 14, E8, F9, 7A, 00, 00, 83, C4, 14, C3, 8B, 44, 24, 04, 66, 8B, 08, 40, 40, 66, 85, C9, 75, F6, 2B, 44, 24, 04, D1, F8, 48, C3, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04...
 
[+]

Entropy:
6.0563

Code size:
172 KB (176,128 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
HP HD Webcam [Fixed]_Monitor

Command:
C:\Program Files\hp hd webcam [fixed]\monitor.exe


Scan monitor.exe - Powered by Reason Core Security