monitor.exe

BACK Monitor Application

Sunplus Innovation Technology Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘HP HD Webcam [Fixed]_Monitor’.
Publisher:
Sunplus Innovation Technology Inc.  (signed and verified)

Product:
BACK Monitor Application

Version:
2, 3, 1, 5

MD5:
6efdcace1a06fd1e7900ed165b85ac0c

SHA-1:
ea55d06e85c21b2442eea4a1e08e348261822c93

SHA-256:
4137ab2aec23223b91f91429c52c0be0c353567740ef17f346c648c141ed9b16

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 12:38:14 PM UTC  (today)

File size:
337.3 KB (345,407 bytes)

Product version:
2, 3, 1, 5

Copyright:
CopyRight (C) 2010

Original file name:
BACK.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\hp hd webcam [fixed]\monitor.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/17/2010 6:00:00 AM

Valid to:
12/7/2011 5:59:59 AM

Subject:
CN=Sunplus Innovation Technology Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sunplus Innovation Technology Inc., L=Hsinchu, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7601821575608B4FA6D6A57BC69A811D

File PE Metadata
Compilation timestamp:
11/26/2010 5:28:06 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:fn0UFN/udcPNtibOZnROZB68jcJi1soYnvBV+UdvrEFp7hKc:5ueP2blZvcJi10vBjvrEH7L

Entry address:
0x19331

Entry point:
E9, 36, AB, FF, FF, E9, 16, FE, FF, FF, 6A, 00, FF, 74, 24, 14, FF, 74, 24, 14, FF, 74, 24, 14, FF, 74, 24, 14, E8, F9, 7A, 00, 00, 83, C4, 14, C3, 8B, 44, 24, 04, 66, 8B, 08, 40, 40, 66, 85, C9, 75, F6, 2B, 44, 24, 04, D1, F8, 48, C3, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04...
 
[+]

Entropy:
6.6828

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
172 KB (176,128 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
HP HD Webcam [Fixed]_Monitor

Command:
C:\Program Files\hp hd webcam [fixed]\monitor.exe


Scan monitor.exe - Powered by Reason Core Security