iCopy.sys

iCopy

Hangzhou Shunwang Information Technology Co., Ltd

It runs as a Windows kernel mode device driver named “iCopy”.
Publisher:
Sunward Information Technology Co.Ltd  (signed by Hangzhou Shunwang Information Technology Co., Ltd)

Product:
iCopy

Description:
iCopy.sys(i386)2010/06/18 周五 10:06:00.49

Version:
0.0.0.5

MD5:
ee7229e6cb3409eefabd1ef0ca201567

SHA-1:
4b922f95e6592290b00691a4428e5a75264e6a60

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 6:04:26 AM UTC  (today)

File size:
14 KB (14,288 bytes)

Product version:
0.0.0.5

Copyright:
Sunward Information Technology Co.Ltd

Original file name:
iCopy.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\icopy.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/26/2009 1:34:08 PM

Valid to:
6/27/2011 1:34:04 PM

Subject:
CN="Hangzhou Shunwang Information Technology Co., Ltd", OU="Hangzhou Shunwang Information Technology Co., Ltd", O="Hangzhou Shunwang Information Technology Co., Ltd", C=CN

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001221B4097E0

File PE Metadata
Compilation timestamp:
7/17/2010 3:29:26 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.10

CTPH (ssdeep):
192:TDuZMPq2tYRpVgoGt/RbZyowJL/eJqiLeu+pU8BfzzSF:TCZEtYRp6Pt/RbZYJLdwMi8Z6

Entry address:
0x1344

Entry point:
55, 8B, EC, 83, EC, 14, 53, 56, 57, 68, 93, 08, 00, 00, 68, C6, 12, 01, 00, 68, CA, 12, 01, 00, E8, B1, 00, 00, 00, 83, C4, 0C, 6A, 21, 59, 33, C0, BF, 80, 15, 01, 00, F3, AB, 8B, 3D, B4, 14, 01, 00, 68, F6, 12, 01, 00, 8D, 45, F4, 50, FF, D7, 8B, 75, 08, 8D, 45, FC, 50, 33, C0, 50, 50, 6A, 22, 8D, 4D, F4, 51, 50, 56, FF, 15, DC, 14, 01, 00, 8B, D8, 85, DB, 7C, 63, 68, 12, 13, 01, 00, 8D, 45, EC, 50, FF, D7, 8D, 45, F4, 50, 8D, 45, EC, 50, FF, 15, CC, 14, 01, 00, 8B, D8, 85, DB, 7D, 0B, FF, 75, FC, FF, 15...
 
[+]

Entropy:
6.5358

Developed / compiled with:
Microsoft Visual C++

Code size:
5 KB (5,120 bytes)

Driver
Display name:
iCopy

Type:
Kernel device driver (KernelDriver)


Scan iCopy.sys - Powered by Reason Core Security