ma1000.sys

iScope Corp

It runs as a Windows kernel mode device driver named “AmScope Device”.
Publisher:
NCUSB  (signed by iScope Corp)

Product:
NCUSB

Description:
NCUSB Driver

Version:
2010.3.18

MD5:
c4540f81d0b6d3fd458bab18f915bf50

SHA-1:
66314e51d9e57c5f2d480f2bac84b151033edaed

SHA-256:
c598fbb9c69aeac55a07d8357a2679fac5458d4fe87f86da09521b90330445e3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 4:12:14 AM UTC  (today)

File size:
25.7 KB (26,296 bytes)

Product version:
2010.3.18

Copyright:
NCUSB

Original file name:
ncusb.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\ma1000.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
12/14/2010 8:20:33 AM

Valid to:
12/15/2011 8:20:30 AM

Subject:
E=highsun_scientific@yahoo.com, CN=iScope Corp, O=iScope Corp, L=Irvine, S=CA, C=US

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012CE5E02D3B

File PE Metadata
Compilation timestamp:
10/14/2011 1:24:57 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
384:yolxevviTcodmBLrMlqWF7wuttMmTM68s8j+Rr942ZfdUb+fuzq:tWvqTclwRwaMmTM65C+9OifuG

Entry address:
0x2E96

Entry point:
8B, FF, 55, 8B, EC, E8, AB, 41, 00, 00, 5D, E9, 1A, FF, FF, FF, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 56, BE, B0, 50, 01, 00, 57, 8B, CE, BF, B0, 50, 01, 00, 33, C0, 3B, CF, 73, 3C, 83, 3E, 2C, 75, 32, 8B, 46, 20, 56, FF, 35, 0C, 57, 01, 00, 89, 35, B4, 50, 01, 00, FF, 75, 08, 85, C0, 74, 09, 68, B2, 2F, 01, 00, FF, D0, EB, 05, E8, C4, 00, 00, 00, 85, C0, 7C, 0E, 83, C6, 2C, 3B, F7, 72, CB, EB, 05, B8, 04, 00, 00, C0, 5F, 5E, 5D, C2, 04, 00, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, A1, B4, 50, 01, 00, B9...
 
[+]

Entropy:
6.4952

Code size:
12.5 KB (12,800 bytes)

Driver
Display name:
AmScope Device

Service name:
AmScope

Type:
Kernel device driver (KernelDriver)

Group:
Base


Scan ma1000.sys - Powered by Reason Core Security