~0000063.TMP

SIVDRIVER

RH Software

Publisher:
Ray Hinchliffe  (signed by RH Software)

Product:
SIVDRIVER

Description:
System Information Viewer A32 Driver

Version:
V4.36 (V4.36)

MD5:
2e5fe824af5749aa600cf682db7d0088

SHA-1:
99c4f16d152fe62645ddc9ad598f41f052a833f9

SHA-256:
29f70e2898117f61c154182be5bba06e7458541dced9a74501b7f154f8350e3e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/20/2024 3:46:47 AM UTC  (today)

File size:
108 KB (110,592 bytes)

Product version:
V4.36

Copyright:
Copyright © Ray Hinchliffe 2001-2013

Original file name:
SIVA32.sys

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\~0000063.tmp

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/4/2013 12:00:00 AM

Valid to:
4/3/2015 11:59:59 PM

Subject:
CN=RH Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=RH Software, L=Aldershot, S=Hants, C=GB

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7D089BDA519BCA3B5970D85EFD408D75

File PE Metadata
Compilation timestamp:
4/14/2013 1:38:17 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
5.12

CTPH (ssdeep):
3072:YUH+qtSknzJTGg0dIKl29CKZAaL3dnmlIgdeJlNQiv63DNmkyr3dWRkQBf8aWDuS:F+qtSkFd0d5lUCKZAO1mlIgdeJlNQivh

Entry address:
0x15A40

Entry point:
B0, FF, DE, 23, 02, 00, 3F, 24, 08, 00, 3E, B5, 10, 00, 5E, B5, 18, 00, 7E, B5, 20, 00, 9E, B5, 28, 00, BE, B5, 30, 00, DE, B5, 38, 00, 5E, B7, 02, 00, 7F, 25, 70, 2F, 6B, 21, 0A, 04, F1, 47, 09, 04, F0, 47, 48, 00, 1E, 22, 28, E6, 01, A0, 11, 04, EB, 47, 03, 40, 40, 6B, 00, 00, 2A, A0, 02, 00, 5F, 24, 18, E6, 02, A0, 21, 76, 20, 48, 40, 00, 9E, 20, 12, 0F, 21, 22, 00, 00, 9E, B4, 44, 00, 3E, B2, 10, 04, E9, 47, 48, 00, 5E, 22, 13, 54, E4, 47, 14, 04, FF, 47, 15, 04, FF, 47, 01, 40, 40, 6B, 0C, 00, 00, F8...
 
[+]

Entropy:
6.2355

Code size:
59.5 KB (60,928 bytes)

Scan ~0000063.TMP - Powered by Reason Core Security