fnsysmgr.exe

FNSYSMGR Dynamic Link Library

FileNet Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘0FileNET System Manager’.
Publisher:
FileNet Corporation  (signed and verified)

Product:
FNSYSMGR Dynamic Link Library

Description:
FNSYSMGR DLL

Version:
330,2006,037,1422

MD5:
efe0aad3a159dd4248fd1a8fc2903847

SHA-1:
29a5980b434cb03aa276ccb3b0874440c5b88d40

SHA-256:
1fc5e3c08d415b6f2bf97319cebfc898c2aea6ab5383e408cba0c6350e631c14

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/29/2024 2:14:29 AM UTC  (today)

Scan engine
Detection
Engine version

Prevx
Heuristic: Suspicious Self Modifying File
3.0.3

File size:
69.8 KB (71,480 bytes)

Product version:
3.3.0

Copyright:
Copyright © 1988, 2003 FileNet Corporation. All rights reserved.

Original file name:
FNSYSMGR.DLL

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
5/24/2005 12:41:32 PM

Valid to:
5/24/2007 12:41:32 PM

Subject:
CN=FileNet Corporation, OU=Engineering, O=FileNet Corporation, L=Costa Mesa, S=California, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
2141F0

File PE Metadata
Compilation timestamp:
2/6/2006 4:43:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x3E42

Entry point:
55, 8B, EC, 6A, FF, 68, 38, 9D, 40, 00, 68, F8, 3F, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, E4, 94, 40, 00, 59, 83, 0D, 78, CA, 40, 00, FF, 83, 0D, 7C, CA, 40, 00, FF, FF, 15, EC, 94, 40, 00, 8B, 0D, D0, C9, 40, 00, 89, 08, FF, 15, E8, 94, 40, 00, 8B, 0D, CC, C9, 40, 00, 89, 08, A1, D8, 94, 40, 00, 8B, 00, A3, 74, CA, 40, 00, E8, 34, 01, 00, 00, 39, 1D, 48, C3, 40, 00, 75, 0C, 68, E2, 3F, 40, 00, FF, 15, E0, 94...
 
[+]

Entropy:
5.4599

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
32 KB (32,768 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
0FileNET System Manager

Command:
C:\filenet\idm\fnsysmgr.exe


Scan fnsysmgr.exe - Powered by Reason Core Security