monitor.exe

BACK Monitor Application

Sunplus Innovation Technology Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Lenovo EasyCamera_Monitor’.
Publisher:
Sunplus Innovation Technology Inc.  (signed and verified)

Product:
BACK Monitor Application

Version:
2, 3, 1, 0

MD5:
ddc4ab85afe4462f70a9671fcd1451c0

SHA-1:
597f1c9858d40dfe7996787813f56bc396a9f7ce

SHA-256:
eaa8edee1f0587299756e6ba8931cc93eea521f9b099f5b4a596307df4b8bf88

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 12:25:38 AM UTC  (today)

File size:
251.2 KB (257,224 bytes)

Product version:
2, 3, 1, 0

Copyright:
CopyRight (C) 2009

Original file name:
BACK.EXE

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, China)

Common path:
C:\Program Files\lenovo easycamera\monitor.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/13/2009 5:30:00 AM

Valid to:
11/14/2010 5:29:59 AM

Subject:
CN=Sunplus Innovation Technology Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sunplus Innovation Technology Inc., L=Hsinchu, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2928081DF4F71970C909C570EDD4AF5D

File PE Metadata
Compilation timestamp:
8/24/2010 7:02:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:XAbCtgIO4WBvgPAHqGK8GYDl02UUbE49K:44WOIfju2UvIK

Entry address:
0x18AD1

Entry point:
E8, CD, 69, 00, 00, E9, 16, FE, FF, FF, 6A, 00, FF, 74, 24, 14, FF, 74, 24, 14, FF, 74, 24, 14, FF, 74, 24, 14, E8, 45, 6A, 00, 00, 83, C4, 14, C3, 8B, 44, 24, 04, 66, 8B, 08, 40, 40, 66, 85, C9, 75, F6, 2B, 44, 24, 04, D1, F8, 48, C3, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04...
 
[+]

Entropy:
6.0490

Code size:
164 KB (167,936 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Lenovo EasyCamera_Monitor

Command:
C:\Program Files\lenovo easycamera\monitor.exe


Scan monitor.exe - Powered by Reason Core Security