MsgLister.sys

MsgHookLister

Zemana Ltd.

Publisher:
http://www.airesoft.co.uk  (signed by Zemana Ltd.)

Product:
MsgHookLister

Description:
MsgLister driver

Version:
2, 0, 0, 0

MD5:
018a9dab36300b3774d29aa75c5c0dd7

SHA-1:
f5eb7feb900f481bb43fe2b91dad5a4802469723

SHA-256:
dc013137b9916e79f289a9dc57e2c6daca6d8b8441ff5debf1f1f1d969b0fa80

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 1:39:24 PM UTC  (today)

File size:
28.8 KB (29,496 bytes)

Product version:
2, 0, 0, 0

Copyright:
Copyright (C) airesoft 2011

Original file name:
MsgLister.sys

File type:
Driver (Win64 SYS)

Language:
English (United Kingdom)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\vmwarednd\286573ce\tools\hook enum tool setwindowshookex\msghooklister\x64\msglister.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/28/2011 2:00:00 AM

Valid to:
12/15/2012 1:59:59 AM

Subject:
CN=Zemana Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Zemana Ltd., L=Sofia, S=Lozenetz, C=BG

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3C15A878642EECC83D8585E96BE375AF

File PE Metadata
Compilation timestamp:
7/2/2011 2:10:10 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
768:0zGVROIzvWUDX6vkGCdRQ8Ao2dIILFm6J:9nOITHkkGUR7Ao2No6J

Entry address:
0x85F4

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, FE, F9, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 5C, 00, 44, 00, 65, 00, 76, 00, 69, 00, 63, 00, 65, 00, 5C, 00, 4D, 00, 73, 00, 67, 00, 4C, 00, 69, 00, 73, 00, 74, 00, 65, 00, 72, 00, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 4D, 73, 67, 48, 6F, 6F, 6B, 4C, 69, 73, 74, 65, 72, 20, 28, 44, 72, 69, 76, 65, 72, 45, 6E, 74, 72, 79, 29, 3A, 20, 4D, 73, 67, 2F, 48, 6F, 6F...
 
[+]

Entropy:
6.3485

Code size:
14 KB (14,336 bytes)

Scan MsgLister.sys - Powered by Reason Core Security