monitor.exe

BACK Monitor Application

Sunplus Innovation Technology Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘FJ Camera_Monitor’.
Publisher:
Sunplus Innovation Technology Inc.  (signed and verified)

Product:
BACK Monitor Application

Version:
2.3.2.27

MD5:
befc0178df14455fd3e0e2a9a711e202

SHA-1:
9cb5f92d679416da46b7159defd86adbc1c1a12c

SHA-256:
7724c8d00b81276791e2fb388655602dba55e8d3723a71653077b7bb9a2c3917

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 6:46:33 AM UTC  (today)

File size:
278.4 KB (285,048 bytes)

Product version:
2.3.2.27

Copyright:
CopyRight (C) 2010-2015

Original file name:
BACK.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\fj camera\monitor.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/26/2011 6:00:00 PM

Valid to:
12/5/2013 5:59:59 PM

Subject:
CN=Sunplus Innovation Technology Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sunplus Innovation Technology Inc., L=Hsinchu, S=Hsinchu, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6D657D8F8000BA22EE6E6937D7F1B80C

File PE Metadata
Compilation timestamp:
8/8/2013 8:58:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:tn0C77uaOmNw6jNQX4UhlKzHmt05EpgH+o3VtgpH:786jNilaHEaH+ov8H

Entry address:
0x20BDE

Entry point:
E8, E0, 88, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 6A, 00, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 59, 89, 00, 00, 83, C4, 14, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 45, 08, 66, 8B, 08, 40, 40, 66, 85, C9, 75, F6, 2B, 45, 08, D1, F8, 48, 5D, C3, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2...
 
[+]

Entropy:
6.4119

Code size:
200 KB (204,800 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
FJ Camera_Monitor

Command:
"C:\Program Files\fj camera\monitor.exe"


Scan monitor.exe - Powered by Reason Core Security