PCCNTMON.EXE

Trend Micro OfficeScan

Trend Micro, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘OfficeScanNT Monitor’.
Publisher:
Trend Micro Inc.  (signed by Trend Micro, Inc.)

Product:
Trend Micro OfficeScan

Description:
Trend Micro OfficeScan Monitor

Version:
8.0.0.3094

MD5:
b63a1ac73fcd62a202e8df32ef58938f

SHA-1:
6dcccdf9ce31e22ad4a54b4b93e22fa63a9e8ff2

SHA-256:
a754b77236ddc1bb19203238331cf70a2695a9f0d5f566360c08b6a43ee1d3cd

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 11:00:32 AM UTC  (today)

File size:
701.3 KB (718,120 bytes)

Product version:
8.0

Copyright:
Copyright (C) 1998-2008 Trend Micro Incorporated. All rights reserved.

Trademarks:
Copyright (C) Trend Micro Inc.

Original file name:
PCCNTMON.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\trend micro\officescan client\pccntmon.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/16/2008 1:00:00 AM

Valid to:
2/17/2011 12:59:59 AM

Subject:
CN="Trend Micro, Inc.", OU=RD, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Trend Micro, Inc.", L=Taipei, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
645212F783F4D7ABA3555729E99CE065

File PE Metadata
Compilation timestamp:
9/30/2008 12:00:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:RO8c13BVOd4IBrJ0eSIhw9lNUrsBigWTPwImxjE4Y0kO:RBjfBZwqrsBvW7B63k

Entry address:
0x526A0

Entry point:
E8, 57, 96, 00, 00, E9, 17, FE, FF, FF, 8B, 44, 24, 04, 66, 8B, 54, 24, 08, EB, 07, 66, 3B, CA, 74, 11, 40, 40, 0F, B7, 08, 66, 85, C9, 75, F1, 66, 39, 10, 74, 02, 33, C0, C3, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, 1B, 47, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 82, 56, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 9C, 06, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08...
 
[+]

Code size:
488 KB (499,712 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
OfficeScanNT Monitor

Command:
"C:\Program Files\trend micro\officescan client\pccntmon.exe" -hidewindow


Scan PCCNTMON.EXE - Powered by Reason Core Security