Monitor.EXE

Monitor Application

NewSoft Technology Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Presto! PVR (1seg)’.
Publisher:
NewSoft  (signed by NewSoft Technology Corporation)

Product:
Monitor Application

Description:
Monitor Application

Version:
1,2000,10155,0

MD5:
44b25b2c5d3a4a6d19f0e28cf1a5eabb

SHA-1:
82c8c5e81f8ba49efceab01d7cb324ad7f15befc

SHA-256:
568fae1e54b4853f8fd95f5026c8aecba837cc0d0357c10df21337d7f6123326

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 2:45:53 PM UTC  (today)

File size:
189.9 KB (194,456 bytes)

Product version:
1,2000,10155,0

Copyright:
Copyright 2005-2009 by NewSoft Technology Corporation. All rights reserved.

Original file name:
Monitor.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\newsoft\presto! pvr (1seg)\monitor.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/28/2010 9:00:00 PM

Valid to:
4/28/2013 8:59:59 PM

Subject:
CN=NewSoft Technology Corporation, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=NewSoft Technology Corporation, L=Hsinchu, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5D9CD7922ADCB963E44057494CEE59BD

File PE Metadata
Compilation timestamp:
6/4/2010 5:38:24 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:nw/73Z0uNW88COCuOfpfK7+TT8q2+4YdzENlu8TkSVqN6abS/9ro:w/73AKekpi7+XqwzQo

Entry address:
0x1DA18

Entry point:
55, 8B, EC, 6A, FF, 68, 68, 1E, 42, 00, 68, 76, DB, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, B0, 05, 42, 00, 59, 83, 0D, F8, 89, 42, 00, FF, 83, 0D, FC, 89, 42, 00, FF, FF, 15, AC, 05, 42, 00, 8B, 0D, EC, 89, 42, 00, 89, 08, FF, 15, A8, 05, 42, 00, 8B, 0D, E8, 89, 42, 00, 89, 08, A1, A4, 05, 42, 00, 8B, 00, A3, F4, 89, 42, 00, E8, 28, 01, 00, 00, 39, 1D, 40, 80, 42, 00, 75, 0C, 68, AC, DB, 41, 00, FF, 15, A0, 05...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
124 KB (126,976 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Presto! PVR (1seg)

Command:
"C:\Program Files\newsoft\presto! pvr (1seg)\monitor.exe"


Scan Monitor.EXE - Powered by Reason Core Security