baizaqjbyjrq.sys

Zemi Interactive Co., Ltd.

It runs as a Windows kernel mode device driver named “baizaqjbyjrq”.
Publisher:
Zemi Interactive Co., Ltd.  (signed and verified)

Version:
1.0.0.0

MD5:
f096fef305ab6fb4b17f529012f0d304

SHA-1:
83b94a611f9d5ce9d9809b3a498687e67d4ce885

SHA-256:
e6ca1a6f2b151253f1ce7ad4d39f0e388589fa9a0853979e15e2b6a3821857a3

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/19/2024 9:22:41 AM UTC  (today)

Scan engine
Detection
Engine version

Kaspersky
not-a-virus:NetTool.Win64.NetFilter
15.0.2.529

Panda Antivirus
Generic Suspicious
17.01.01.06

Qihoo 360 Security
HEUR/QVM00.1.Malware.Gen
1.0.0.1120

File size:
293.5 KB (300,560 bytes)

Product version:
1.0.0.0

Copyright:
Copyright (C) 2015

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\baizaqjbyjrq.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/9/2013 8:00:00 AM

Valid to:
8/9/2014 7:59:59 AM

Subject:
CN="Zemi Interactive Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Zemi Interactive Co., Ltd.", L=SeoChoGu, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4505E9AC8D288D763A1088ED1E2C8A60

File PE Metadata
Compilation timestamp:
1/6/2014 4:12:49 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

Entry address:
0x14000

Entry point:
55, 8B, EC, 83, EC, 14, 53, 56, 57, E9, 00, 00, 00, 00, 60, 8D, 64, 24, 20, E9, 00, 00, 00, 00, E9, 00, 00, 00, 00, 9C, 9C, 60, 8D, 64, 24, 28, E8, 67, A4, FF, FF, E9, 00, 00, 00, 00, 9C, 8D, 64, 24, 04, E8, 68, D1, FE, FF, E8, 00, 00, 00, 00, 8B, 45, 0C, C6, 04, 24, 6C, 9C, E9, 00, 00, 00, 00, E9, 00, 00, 00, 00, 89, 44, 24, 04, 68, C9, 26, CD, 70, E8, 00, 00, 00, 00, 60, E8, 00, 00, 00, 00, 8D, 64, 24, 30, E8, 14, ED, FE, FF, 66, C1, FE, 05, 8B, F0, 84, C6, E8, 00, 00, 00, 00, F5, 29, DB, 38, D3, 3B, F3...
 
[+]

Entropy:
6.9598

Developed / compiled with:
Microsoft Visual C++

Code size:
62 KB (63,488 bytes)

Driver
Display name:
baizaqjbyjrq

Type:
Kernel device driver (KernelDriver)


Scan baizaqjbyjrq.sys - Powered by Reason Core Security