Filemon.exe

Sysinternals Filemon

Microsoft Corporation

Publisher:
Sysinternals  (signed by Microsoft Corporation)

Product:
Sysinternals Filemon

Description:
File system monitor

Version:
7.04

MD5:
86d34c2ddb5aa222a9b1fd2ea3348433

SHA-1:
ee7e236d75e8739dbe5d14fe2fbe96d9b5a8246c

SHA-256:
78549e59cabd15df7c9bd17a1e965e589012c61e2692ae8e78561bcac319ae4e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
11/24/2024 10:42:09 AM UTC  (today)

File size:
730.8 KB (748,344 bytes)

Product version:
7.04

Copyright:
Copyright © 1996-2006

Original file name:
Filemon.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\filemon.exe

Digital Signature
Authority:
Microsoft Corporation

Valid from:
4/4/2006 3:43:46 PM

Valid to:
10/4/2007 3:53:46 PM

Subject:
CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA, OU=Copyright (c) 2000 Microsoft Corp., O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
61469ECB000400000065

File PE Metadata
Compilation timestamp:
11/6/2006 2:07:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:9lrOaxCtkFW1ZJBsB6f5r7o2AIBMdldFZOhoLb3FfO5o6Lz3Bcau:6ykrsB6fhZw7FB8R33Bcau

Entry address:
0xBB4A

Entry point:
E8, 4C, 71, 00, 00, E9, 16, FE, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 48, A7, 43, 00, 89, 0D, 44, A7, 43, 00, 89, 15, 40, A7, 43, 00, 89, 1D, 3C, A7, 43, 00, 89, 35, 38, A7, 43, 00, 89, 3D, 34, A7, 43, 00, 66, 8C, 15, 60, A7, 43, 00, 66, 8C, 0D, 54, A7, 43, 00, 66, 8C, 1D, 30, A7, 43, 00, 66, 8C, 05, 2C, A7, 43, 00, 66, 8C, 25, 28, A7, 43, 00, 66, 8C, 2D, 24, A7, 43, 00, 9C, 8F, 05, 58, A7, 43, 00, 8B, 45, 00, A3, 4C, A7, 43, 00, 8B, 45, 04, A3, 50, A7, 43, 00, 8D, 45, 08, A3, 5C, A7, 43, 00, 8B...
 
[+]

Entropy:
6.4052

Code size:
100 KB (102,400 bytes)

The file Filemon.exe has been discovered within the following program.

PIXELRULER  by Mioplanet
www.mioplanet.com
About 4% of users remove it
 
Powered by Should I Remove It?

The file Filemon.exe has been seen being distributed by the following URL.