iSharePp.sys

Pnp Driver for "iShareDisk"

WDKTestCert Administrator

It runs as a Windows kernel mode device driver named “iSharePnp”.
Publisher:
www.isharedisk.com  (signed by WDKTestCert Administrator)

Product:
Pnp Driver for "iShareDisk"

Description:
www.isharedisk.com

Version:
1.6.2566.20140224

MD5:
1d9a4cded302ccbce9bb4bafc9239e49

SHA-1:
8d3fdb1211cc9eef2ef48b9975d05f9de9934faa

SHA-256:
01964ad16e86a38a2a947cfcf048f0346dfc56dbf4b86436dfb6d56520a88369

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 4:04:06 AM UTC  (today)

File size:
37.3 KB (38,168 bytes)

Product version:
1.6.2566.20140224

Copyright:
Copyright (C) 2013 All Right Reserved

Original file name:
iSharePp.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\isharepp.sys

Digital Signature
Authority:
WDKTestCert Administrator

Subject:
CN="WDKTestCert Administrator,130246594928449691"

Issuer:
CN="WDKTestCert Administrator,130246594928449691"

Serial number:
197723101DF26D9C4684877081C5BD37

File PE Metadata
Compilation timestamp:
2/24/2014 4:08:10 PM

OS version:
6.3

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
12.0

CTPH (ssdeep):
768:gTJg/gqEa0a7KnDMFsvk1bmTDVteBOR0iZu6Pyvn:g1EtEKKnDMF2kVmTuO0i1w

Entry address:
0xA000

Entry point:
8B, FF, 55, 8B, EC, E8, 06, 00, 00, 00, 5D, E9, 3E, 7C, FF, FF, 8B, FF, 55, 8B, EC, 51, 51, A1, 88, 92, 40, 00, B9, 4E, E6, 40, BB, 85, C0, 74, 04, 3B, C1, 75, 18, 0F, 31, 35, 88, 92, 40, 00, 89, 55, FC, A3, 88, 92, 40, 00, 75, 07, 8B, C1, A3, 88, 92, 40, 00, F7, D0, A3, 84, 92, 40, 00, 8B, E5, 5D, C3, 90, A0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 90, A6, 00, 00, 0C, 80, 00, 00, 88, A0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B6, A6, 00, 00, 04, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.1279

Code size:
29.5 KB (30,208 bytes)

Driver
Display name:
iSharePnp

Type:
Kernel device driver (KernelDriver)

Group:
iSharePnpGroup


Scan iSharePp.sys - Powered by Reason Core Security