hemffdshow.ax

ffdshow

KINGDOM COMMUNICATION ASSOCIATED LTD.

Publisher:
KINGDOM COMMUNICATION ASSOCIATED LTD.  (signed and verified)

Product:
ffdshow

Description:
DirectShow and VFW video and audio decoding/encoding/processing filter

Version:
1.2.4486.3

MD5:
d52d38aba52307330890cae8dce000d7

SHA-1:
5f321e890920bd4a7a0e01e814c3f328d4da0567

SHA-256:
0cd02f0baac3c85664ece42b8607b7a64d7467a3874cfe691fb12ee28345cafc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/1/2024 3:33:33 AM UTC  (today)

File size:
4 MB (4,171,768 bytes)

Product version:
1.2.4486.3

Copyright:
Copyright © 2002-2014

Trademarks:
GNU GPL

Original file name:
ffdshow.ax

Common path:
C:\Windows\System32\hemffdshow.ax

Digital Signature
Authority:
Symantec Corporation

Valid from:
10/14/2015 8:00:00 AM

Valid to:
10/14/2016 7:59:59 AM

Subject:
CN=KINGDOM COMMUNICATION ASSOCIATED LTD., OU=RD, O=KINGDOM COMMUNICATION ASSOCIATED LTD., L=Taipei, S=Taiwan, C=TW

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
6FE4D897B5BE6CFE2223DE75CCC6D9B1

File PE Metadata
Compilation timestamp:
3/3/2014 11:15:30 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:zIMBhPjeD5KBVWiWZEZMpnEN5w+mm2oRATLfM9JNIe+D1JF+NSPgxak+9xSziFev:zN8TCaceFewTRIY8z1nVXvZSiYQ

Entry address:
0x296940

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 83, CC, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 51, C7, 01, FC, 87, 33, 10, E8, FD, CC, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, F1, E8, E3, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 52, 00, 00, 00, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 83, C1, 09, 51, 83, C0, 09, 50, E8, A7, B0, 00, 00, F7, D8, 59, 1B, C0, 59, 40, 5D, C2, 04, 00, FF, 35, A0, 86, 49, 10, FF, 15, F0, E1, 2E, 10...
 
[+]

Entropy:
6.5159

Code size:
2.9 MB (3,056,128 bytes)

ActiveX Install
Name:
{309E27CA-1FDC-4AD2-A3AA-0FF47085E5A6}


Scan hemffdshow.ax - Powered by Reason Core Security