h5g7qzo8.sys

VBA32

VirusBlokAda

It runs as a Windows 64-bit kernel mode device driver named “Vba32 Armour Driver”.
Publisher:
VirusBlokAda Ltd.  (signed by VirusBlokAda)

Product:
VBA32

Description:
Vba32 AntiRootkit driver

Version:
4.0

MD5:
04f76bc3aff4dd42a0ff860c8e70acc8

SHA-1:
396ab25b0856d12d8f8dbfd819e014a19851af60

SHA-256:
4f064574c61d3d6f6d2d41c0b6dedf978891b23c1ce2ecc892ecd9309118c771

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 6:13:51 AM UTC  (today)

File size:
35.1 KB (35,904 bytes)

Product version:
3.12

Copyright:
Copyright © VirusBlokAda Ltd. All rights reserved.1993-2009

Original file name:
Vba32Arr.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\h5g7qzo8.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/29/2009 4:00:00 PM

Valid to:
1/30/2010 3:59:59 PM

Subject:
CN=VirusBlokAda, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=VirusBlokAda, L=Minsk, S=Minsk, C=BY

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6E7249C3107FF962E1BA82D81A50088E

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
768:uYczpz5fopK1jHHeqevAR37BvCtooLTJbIK5:uxzpz5wpeHeq+O7BJoH5d

Entry point:
8B, FF, 55, 8B, EC, 81, EC, E4, 00, 00, 00, 56, 8B, 75, 08, 57, 56, E8, 84, 39, 00, 00, 33, FF, 3B, C7, A3, F8, 67, 01, 00, 75, 0A, B8, 01, 00, 00, C0, E9, C0, 01, 00, 00, 6A, 01, FF, 15, 18, 63, 01, 00, 33, C9, 64, A1, 34, 00, 00, 00, 85, C0, 74, 18, 8B, 90, 90, 02, 00, 00, 8A, 52, 01, 88, 15, 40, 68, 01, 00, 66, 8B, 48, 02, 8B, 40, 10, EB, 16, 64, A1, 2C, 01, 00, 00, 66, 25, 00, F0, 2D, 00, 10, 00, 00, 66, 81, 38, 4D, 5A, 75, F4, 66, 89, 0D, 60, 68, 01, 00, 89, 45, 08, 6A, 2C, 8D, 45, 9C, 50, E8, 54, 37...
 
[+]

Entropy:
6.6005

Driver
Display name:
Vba32 Armour Driver

Service name:
h5g7qzo8

Type:
Kernel device driver (KernelDriver)

Group:
Vba System


Scan h5g7qzo8.sys - Powered by Reason Core Security