monitor.exe

BACK Monitor Application

Sunplus Innovation Technology Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Lenovo EasyCamera_Monitor’.
Publisher:
Sunplus Innovation Technology Inc.  (signed and verified)

Product:
BACK Monitor Application

Version:
2, 3, 1, 12

MD5:
3e2366bc49e2c59c3f7ff2b3b62930f6

SHA-1:
dd6e6c1b3efcb9355ba8d87b9e19d3137bbff8c3

SHA-256:
01b3c454ea059e9fc421d4934fc6894031290c34b054cb6906152f8333316850

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/14/2024 4:34:40 PM UTC  (today)

File size:
293.4 KB (300,408 bytes)

Product version:
2, 3, 1, 12

Copyright:
CopyRight (C) 2010

Original file name:
BACK.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\lenovo easycamera\monitor.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/27/2011 12:00:00 AM

Valid to:
12/5/2013 11:59:59 PM

Subject:
CN=Sunplus Innovation Technology Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sunplus Innovation Technology Inc., L=Hsinchu, S=Hsinchu, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6D657D8F8000BA22EE6E6937D7F1B80C

File PE Metadata
Compilation timestamp:
2/6/2012 4:01:58 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:tRJKi8Z2zMj3Ly3QHvyYPRgcdOyxzdUnZSD/WPGR6:tFMjbHH2j0UnsSu8

Entry address:
0x194C1

Entry point:
E8, A1, 67, 00, 00, E9, 16, FE, FF, FF, 6A, 0A, 6A, 00, FF, 74, 24, 0C, E8, 4E, 6A, 00, 00, 83, C4, 0C, C3, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A4, 01, 00, 00, 81, F9, 00, 01, 00, 00, 72, 1F, 83, 3D, 44, B1, 43, 00, 00, 74, 16...
 
[+]

Code size:
164 KB (167,936 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Lenovo EasyCamera_Monitor

Command:
C:\Program Files\lenovo easycamera\monitor.exe


Scan monitor.exe - Powered by Reason Core Security