HookReg.sys

Rising AntiVirus 2008

BEIJING RISING SCIENCE AND TECHNOLOGY CORPORATION LIMITED

It runs as a Windows kernel mode device driver named “HookReg”.
Publisher:
Beijing Rising Technology Co., Ltd  (signed by BEIJING RISING SCIENCE AND TECHNOLOGY CORPORATION LIMITED)

Product:
Rising AntiVirus 2008

Description:
HookReg

Version:
22, 0, 0, 23

MD5:
1b7562bdb09937602da6bc37535090e4

SHA-1:
bf8188c745d0d8fb5484e8cdeed7d05631ca4028

SHA-256:
7fb605577ef4759aff42155866d74ca48d587f65dbda4df2d8994fac4dc52226

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 10:35:12 PM UTC  (today)

File size:
36.2 KB (37,104 bytes)

Product version:
22, 0, 0, 0

Copyright:
Copyright (C) 2007

Original file name:
HookReg.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\hookreg.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/29/2008 9:00:00 AM

Valid to:
1/29/2009 8:59:59 AM

Subject:
CN=BEIJING RISING SCIENCE AND TECHNOLOGY CORPORATION LIMITED, OU=Networking Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=BEIJING RISING SCIENCE AND TECHNOLOGY CORPORATION LIMITED, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2FCE873CC7EC049DF005CA0E665EC087

File PE Metadata
Compilation timestamp:
2/28/2008 2:45:13 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.10

CTPH (ssdeep):
768:78yWArhE051MMM+MuqdY0qP6WsehoLAmEbIr:L151MM1ifqP6WsVLgk

Entry address:
0xBB6

Entry point:
55, 8B, EC, 83, EC, 14, E8, E1, 40, 00, 00, 68, 84, 00, 00, 00, E8, B5, F8, FF, FF, 85, C0, 59, 74, 09, 8B, C8, E8, 19, 3E, 00, 00, EB, 02, 33, C0, 85, C0, A3, A4, 63, 01, 00, 75, 0A, B8, 01, 00, 00, C0, E9, 62, 04, 00, 00, 56, 6A, 44, 5E, 56, E8, 88, F8, FF, FF, 85, C0, 59, 74, 09, 8B, C8, E8, 7E, 35, 00, 00, EB, 02, 33, C0, 85, C0, A3, 9C, 63, 01, 00, 75, 22, 8B, 0D, A4, 63, 01, 00, 85, C9, 8B, F1, 74, 0C, E8, 4C, 40, 00, 00, 56, FF, 15, E8, 4D, 01, 00, B8, 01, 00, 00, C0, E9, 1C, 04, 00, 00, 56, E8, 47...
 
[+]

Entropy:
6.4582

Developed / compiled with:
Microsoft Visual C++

Code size:
19.6 KB (20,096 bytes)

Driver
Display name:
HookReg

Type:
Kernel device driver (KernelDriver)


Scan HookReg.sys - Powered by Reason Core Security