PCCNTMON.EXE

Trend Micro OfficeScan

Trend Micro, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘OfficeScanNT Monitor’.
Publisher:
Trend Micro Inc.  (signed by Trend Micro, Inc.)

Product:
Trend Micro OfficeScan

Description:
Trend Micro OfficeScan Monitor

Version:
10.6.0.3247

MD5:
3bafefbd60fca0ffab52a3f4e915c264

SHA-1:
c180c40a8d20e7d74f75c4a6961f5dbcd6b64d1e

SHA-256:
1736c736fe3d702b3d2585b7b4620b647b36897988aa94be9af0732f17ed33b0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 10:28:50 AM UTC  (today)

File size:
1.4 MB (1,496,656 bytes)

Product version:
10.6

Copyright:
Copyright (C) 1998 - 2013 Trend Micro Incorporated. All rights reserved.

Trademarks:
Copyright (C) Trend Micro Inc.

Original file name:
PCCNTMON.EXE

File type:
Executable application (Win32 EXE)

Language:
Spanish

Common path:
C:\Program Files\trend micro\officescan client\pccntmon.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/26/2011 6:00:00 PM

Valid to:
2/15/2013 5:59:59 PM

Subject:
CN="Trend Micro, Inc.", OU=RD, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Trend Micro, Inc.", L=Taipei, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6326C00EAD256B6837EEB29B5EE84720

File PE Metadata
Compilation timestamp:
1/29/2013 4:03:31 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:kJTTpW3wO7/TRKda1quSxLMAnNBodpXR:STc/TEda1kxnNadpXR

Entry address:
0x7E7B0

Entry point:
E8, 3B, AE, 00, 00, E9, 17, FE, FF, FF, 8B, 44, 24, 04, 66, 8B, 54, 24, 08, EB, 07, 66, 3B, CA, 74, 11, 40, 40, 0F, B7, 08, 66, 85, C9, 75, F1, 66, 39, 10, 74, 02, 33, C0, C3, 8B, 44, 24, 04, 8B, D0, 66, 8B, 08, 40, 40, 66, 85, C9, 75, F6, 66, 8B, 4C, 24, 08, 48, 48, 3B, C2, 74, 05, 66, 39, 08, 75, F5, 66, 8B, 10, 66, 2B, D1, 66, F7, DA, 1B, D2, F7, D2, 23, C2, C3, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, CD, 33, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57...
 
[+]

Entropy:
6.0235

Code size:
788 KB (806,912 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
OfficeScanNT Monitor

Command:
"C:\Program Files\trend micro\officescan client\pccntmon.exe" -hidewindow


Scan PCCNTMON.EXE - Powered by Reason Core Security