monitor.exe

BACK Monitor Application

Sunplus Innovation Technology Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘1.3M WebCam_Monitor’.
Publisher:
Sunplus Innovation Technology Inc.  (signed and verified)

Product:
BACK Monitor Application

Version:
2, 3, 1, 0

MD5:
18cd4a5edda45ea94ba1abf07b81b4ae

SHA-1:
f5c383498aa3b60a8bcac3c79c52dcbad23de3a8

SHA-256:
aca403030e9c8b0a8070c83774130df67466c9a8c13b855be96e4ed0ab0c8754

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/10/2024 7:49:18 AM UTC  (today)

File size:
247.2 KB (253,128 bytes)

Product version:
2, 3, 1, 0

Copyright:
CopyRight (C) 2009

Original file name:
BACK.EXE

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\Program Files\1.3m webcam\monitor.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/13/2009 1:00:00 AM

Valid to:
11/14/2010 12:59:59 AM

Subject:
CN=Sunplus Innovation Technology Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sunplus Innovation Technology Inc., L=Hsinchu, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2928081DF4F71970C909C570EDD4AF5D

File PE Metadata
Compilation timestamp:
12/10/2009 9:55:38 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:du8TjWqKPrRIOX+ZriQI8g3Z9dtDP00eBLFU6o4vPqo:cPrSjrzIhHP00wLFDvio

Entry address:
0x19481

Entry point:
E8, 33, 69, 00, 00, E9, 16, FE, FF, FF, 6A, 00, FF, 74, 24, 14, FF, 74, 24, 14, FF, 74, 24, 14, FF, 74, 24, 14, E8, AB, 69, 00, 00, 83, C4, 14, C3, 8B, 44, 24, 04, 66, 8B, 08, 40, 40, 66, 85, C9, 75, F6, 2B, 44, 24, 04, D1, F8, 48, C3, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04...
 
[+]

Code size:
164 KB (167,936 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
1.3M WebCam_Monitor

Command:
C:\Program Files\1.3m webcam\monitor.exe


Scan monitor.exe - Powered by Reason Core Security