ncvet.dll

Beijing Joychina Network Technologies Co., Ltd.

It runs as a Windows kernel mode device driver named “ncvet.dll”.
Publisher:

Description:
ncvet.dll

Version:
1.0.0.2 built by: WinDDK

MD5:
3d693164fa9cc6d6557080b56e33d457

SHA-1:
4a9c2348b3e4c36c75bed1f6a5498580a3fcf60f

SHA-256:
2ab9c2ae215f03340462b110ec6679fa7f2533b15e6933a76da0f5094cf43e89

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 2:26:45 PM UTC  (today)

File size:
30 KB (30,744 bytes)

Product version:
1.0.0.2

Copyright:
Copyleft (C) Beijing Joychina Network Technologies Co., Ltd. 2011

Original file name:
ncvet.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\roaming\joychina\ncvet.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/26/2010 8:00:00 AM

Valid to:
10/19/2012 7:59:59 AM

Subject:
CN="Beijing Joychina Network Technologies Co., Ltd.", OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing Joychina Network Technologies Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6A8C137C679FD04EA21E321FF042670F

File PE Metadata
Compilation timestamp:
4/13/2011 6:02:46 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

Entry address:
0x4B6F

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 07, FF, FF, FF, CC, 5C, 00, 44, 00, 6F, 00, 73, 00, 44, 00, 65, 00, 76, 00, 69, 00, 63, 00, 65, 00, 73, 00, 5C, 00, 4E, 00, 43, 00, 44, 00, 72, 00, 69, 00, 76, 00, 65, 00, 72, 00, 00, 00, 5C, 00, 44, 00, 65, 00, 76, 00, 69, 00, 63, 00, 65, 00, 5C, 00, 4E, 00, 43, 00, 44, 00, 72, 00, 69, 00, 76, 00, 65, 00, 72, 00, 00, 00, 28, 4C, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, DE, 4F, 00, 00, A0, 3E, 00, 00, 08, 4C, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 88, 50, 00...
 
[+]

Entropy:
6.4733

Code size:
17.1 KB (17,536 bytes)

Driver
Display name:
ncvet.dll

Type:
Kernel device driver (KernelDriver)


Scan ncvet.dll - Powered by Reason Core Security