monitor.exe

BACK Monitor Application

Sunplus Innovation Technology Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘FJ Camera_Monitor’.
Publisher:
Sunplus Innovation Technology Inc.  (signed and verified)

Product:
BACK Monitor Application

Version:
2, 3, 2, 6

MD5:
c2c3244abeb73662398765d42e268e11

SHA-1:
8cccbf0d55df82dc8d199368c4efde2607c0b5ee

SHA-256:
57f6387bf0e50318f0d24f9e4fcdcaa87a993d13307fd71a215c5beff3d2e807

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 4:12:37 AM UTC  (today)

File size:
272.9 KB (279,416 bytes)

Product version:
2, 3, 2, 6

Copyright:
CopyRight (C) 2010-2015

Original file name:
BACK.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\fj camera\monitor.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/27/2011 9:00:00 AM

Valid to:
12/6/2013 8:59:59 AM

Subject:
CN=Sunplus Innovation Technology Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sunplus Innovation Technology Inc., L=Hsinchu, S=Hsinchu, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6D657D8F8000BA22EE6E6937D7F1B80C

File PE Metadata
Compilation timestamp:
2/22/2012 10:36:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:UcxX+IFcOaX6IJmdNKnXJVnbPKrJjx70A1:3VazJkCZdPKrJBx

Entry address:
0x1C751

Entry point:
E8, 21, 78, 00, 00, E9, 16, FE, FF, FF, 55, 8B, EC, 83, EC, 14, 53, 56, 57, 8B, 7D, 08, 33, DB, 3B, FB, 74, 21, 39, 5D, 0C, 76, 21, 3B, FB, 0F, 84, B8, 00, 00, 00, FF, 75, 0C, 57, E8, 6D, 7C, 00, 00, 3B, 45, 0C, 59, 59, 72, 27, 88, 1F, EB, 05, 39, 5D, 0C, 74, DF, E8, BA, 08, 00, 00, 6A, 16, 5E, 53, 53, 53, 53, 53, 89, 30, E8, B9, E0, FF, FF, 83, C4, 14, 8B, C6, E9, 83, 00, 00, 00, FF, 75, 10, 8D, 4D, EC, E8, B5, E3, FF, FF, 8B, F7, 38, 1E, 74, 62, 8A, 0F, 8B, 55, F0, 0F, B6, C1, 03, C2, 8A, 50, 1D, F6, C2...
 
[+]

Entropy:
6.1987

Code size:
184 KB (188,416 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
FJ Camera_Monitor

Command:
C:\Program Files\fj camera\monitor.exe


Scan monitor.exe - Powered by Reason Core Security