hardwaresimulate.sys

Wuhan os-easy technology co., ltd

It runs as a Windows kernel mode device driver named “HardWareSimulate”.
Publisher:
Wuhan os-easy technology co., ltd  (signed and verified)

MD5:
930c8fc1fb4eca1da49a4b56d13bad81

SHA-1:
f89b5da6e01174e328325e4766229fd472179270

SHA-256:
6a401f9e9970e6b0bb8f1ccda8c8fffd46b63cd45b05d2c2a2a2a24e971b3992

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/26/2024 1:34:38 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
probably unknown NewHeur_PE virus
6.3.12010.0

File size:
26.8 KB (27,392 bytes)

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\hardwaresimulate.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/20/2010 8:00:00 AM

Valid to:
12/20/2011 7:59:59 AM

Subject:
CN="Wuhan os-easy technology co., ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Wuhan os-easy technology co., ltd", L=Wuhan, S=Hubei, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1AC973C465F546C5855FC2085FF20F8D

File PE Metadata
Compilation timestamp:
6/14/2011 3:21:25 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
768:iHCd1TAIAQg1mTn8ovRQ+7+fEML3E2mFK:iUxv5MgNFK

Entry address:
0x81C3

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 33, FE, FF, FF, CC, 47, 65, 74, 53, 79, 73, 50, 61, 72, 61, 6D, 41, 72, 65, 61, 41, 64, 72, 20, 72, 65, 73, 75, 6C, 74, 20, 3D, 20, 25, 64, 00, CC, 5C, 00, 44, 00, 6F, 00, 73, 00, 44, 00, 65, 00, 76, 00, 69, 00, 63, 00, 65, 00, 73, 00, 5C, 00, 48, 00, 61, 00, 72, 00, 64, 00, 57, 00, 61, 00, 72, 00, 65, 00, 53, 00, 69, 00, 6D, 00, 75, 00, 00, 00, 5C, 00, 44, 00, 65, 00, 76, 00, 69, 00, 63, 00, 65, 00, 5C, 00, 64, 00, 65, 00, 76, 00, 48, 00, 61, 00, 72, 00, 64...
 
[+]

Entropy:
6.5406

Code size:
15 KB (15,360 bytes)

Driver
Display name:
HardWareSimulate

Type:
Kernel device driver (KernelDriver)


Scan hardwaresimulate.sys - Powered by Reason Core Security