hxdnetmon.sys

Windows Win 7 DDK driver

NetZone Info-Tech Co., Ltd., Shanghai

The file hxdnetmon.sys, “Network Monitor Driver” by NetZone Info-Tech Co.,, Shanghai has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a Windows kernel mode device driver named “hxdnetmon Service”.
Publisher:
Windows (R) Win 7 DDK provider  (signed by NetZone Info-Tech Co., Ltd., Shanghai)

Product:
Windows (R) Win 7 DDK driver

Description:
Network Monitor Driver

Version:
6.1.7600.16385 built by: WinDDK

MD5:
03d2331f26180858ceaa12fa2835d90a

SHA-1:
f131aa3e63eec598c016f488358be566040bd8d2

SHA-256:
bfd7be46f2fd5af3fb1057352bd2b65c5e0867597945f1e8d87a4e448b542d29

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 9:08:38 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.NetZoneInfoTechCoShanghai
16.2.12.17

File size:
51 KB (52,272 bytes)

Product version:
6.1.7600.16385

Copyright:
© Netzonesoft Corporation. All rights reserved.

Original file name:
hxdnetmon.sys

File type:
Driver (Win32 SYS)

Language:
Language Neutral

Common path:
C:\Windows\System32\drivers\hxdnetmon.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/26/2011 7:00:00 AM

Valid to:
8/5/2012 6:59:59 AM

Subject:
CN="NetZone Info-Tech Co., Ltd., Shanghai", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="NetZone Info-Tech Co., Ltd., Shanghai", L=Shanghai, S=Shanghai, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
00F1D32C1B972DF4D97FEF5EE83B90E5

File PE Metadata
Compilation timestamp:
2/2/2012 4:11:16 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
768:psw3hmxIGT8sY8vH884nVIwm9sv3afJtOhNDtUQcMP6IIL3E2mMZ:ppxmHgX814CwmGafJksQdP2gNMZ

Entry address:
0x9767

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 8F, FD, FF, FF, CC, 68, 00, 78, 00, 64, 00, 6E, 00, 65, 00, 74, 00, 6D, 00, 6F, 00, 6E, 00, 00, 00, B4, 98, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, F2, 9A, 00, 00, D8, 8F, 00, 00, DC, 97, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 58, 9B, 00, 00, 00, 8F, 00, 00, F4, 97, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FA, 9F, 00, 00, 18, 8F, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 36, 9B, 00, 00, 28, 9B, 00, 00, 14, 9B, 00...
 
[+]

Entropy:
6.7087

Code size:
37.5 KB (38,400 bytes)

Driver
Display name:
hxdnetmon Service

Service name:
hxdnetmon

Type:
Kernel device driver (KernelDriver)

Group:
NDIS


Remove hxdnetmon.sys - Powered by Reason Core Security