vsnp2std.exe

CameraMonitor Application

Sonix

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘snp2std’.
Scan vsnp2std.exe - Powered by Reason Core Security
Publisher:
Sonix

Product:
CameraMonitor Application

Version:
1, 0, 9, 0

MD5:
2214de16bda28adf2e8b58a45c3fc1be

SHA-1:
2d6511f72cb6d506c53c1ebc7a51151e113e2fdc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/9/2016 4:46:57 AM UTC  (a few moments ago)

File size:
660 KB (675,840 bytes)

Product version:
1, 0, 9, 0

Copyright:
Copyright 2002-2005

Original file name:
CameraMonitor.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\vsnp2std.exe

File PE Metadata
Compilation timestamp:
4/21/2006 8:32:56 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:3Ej4I8z08/vPncpthbe/4c83C7shUgYnB8/85/8p1:YG083Pn4nbhc8S7aUtB8/85/8p1

Entry address:
0x30507

Entry point:
E8, A8, 9A, 00, 00, E9, 16, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 88, 17, 48, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 88, 17, 48, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Code size:
436 KB (446,464 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
snp2std

Command:
C:\windows\vsnp2std.exe


Scan vsnp2std.exe - Powered by Reason Core Security