max_drv.sys

NGO

It runs as a Windows kernel mode device driver named “Mark Finder Driver”.
Publisher:
NGO  (signed and verified)

MD5:
46fd4eb0787c5fa89661bd3e8c528d0d

SHA-1:
cb9dfbf78ef92e7580487c3535d2dbb232c4a7fe

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 9:38:31 PM UTC  (today)

File size:
4.4 KB (4,480 bytes)

File type:
Driver (Win32 SYS)

Common path:
C:\Documents and Settings\{user}\Application data\kw\max_drv.sys

Digital Signature
Signed by:

Authority:
NGO

Valid from:
9/15/2012 1:56:46 AM

Valid to:
12/31/2039 6:59:59 PM

Subject:
CN=NGO

Issuer:
CN=NGO

Serial number:
920F37E55EC52C804105CE8FF6916091

File PE Metadata
Compilation timestamp:
9/4/2012 10:39:06 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
96:b/1Pwcbk7CXWEbNyAcDIZUoj+AIIiLdiv:xPHk7CXW2YPsSoaAIIiLdI

Entry address:
0xB69

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 8D, FF, FF, FF, CC, CC, CC, A4, 0B, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, E8, 0C, 00, 00, 80, 09, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, DC, 0B, 00, 00, E6, 0B, 00, 00, F4, 0B, 00, 00, 0E, 0C, 00, 00, 1E, 0C, 00, 00, 36, 0C, 00, 00, 4A, 0C, 00, 00, 6A, 0C, 00, 00, 86, 0C, 00, 00, 9C, 0C, 00, 00, B4, 0C, 00, 00, CA, 0C, 00, 00, D8, 0C, 00, 00, 00, 00, 00, 00, 0B, 05, 5A, 77, 43, 6C, 6F, 73, 65, 00, 73, 05, 5A...
 
[+]

Code size:
1.9 KB (1,920 bytes)

Driver
Display name:
Mark Finder Driver

Service name:
MarkFinderService

Type:
Kernel device driver (KernelDriver)


Scan max_drv.sys - Powered by Reason Core Security