ncvhook.sys

Net Control 2

Vadim Parkhomchuk, I.E.

It runs as a Windows kernel mode device driver named “ncvhook”.
Publisher:
Net Software 2  (signed by Vadim Parkhomchuk, I.E.)

Product:
Net Control 2

Description:
Net Control 2 Video Hook Miniport

Version:
7.0 built by: WinDDK

MD5:
843c8b0dec260ef371c2f8f949f6ec8b

SHA-1:
7b361fc449acc2c4a1948db5583757ca5c31fe8f

SHA-256:
ace34f25e94f1602724612fd32031faa5030d98876aee47426b752a81f388ff7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 5:50:18 AM UTC  (today)

File size:
6.7 KB (6,896 bytes)

Product version:
7.0

Copyright:
Copyright (C) Net Software 2 2000-2007

Original file name:
ncvhook.sys

File type:
Driver (Win32 SYS)

Language:
Language Neutral

Common path:
C:\Windows\System32\drivers\ncvhook.sys

Digital Signature
Authority:
The USERTRUST Network

Valid from:
12/3/2007 2:00:00 AM

Valid to:
12/3/2008 1:59:59 AM

Subject:
CN="Vadim Parkhomchuk, I.E.", O="Vadim Parkhomchuk, I.E.", STREET=Dubrovskaya str. 8/1-30, L=Brest, S=Brest, PostalCode=224000, C=BY

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
6AA07CEF4E11ADB5961BFC00A92CABF7

File PE Metadata
Compilation timestamp:
9/30/2007 3:54:30 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.10

CTPH (ssdeep):
96:BgMEDQegQV1E4ZZl7yMhxjtIwH4xSvsUg23PXzV4ik4vQdk4p1e9:9ED1FVnyMTCHpUg2PJgBM9

Entry address:
0x705

Entry point:
8B, FF, 55, 8B, EC, A1, 84, 06, 01, 00, 85, C0, B9, 40, BB, 00, 00, 74, 04, 3B, C1, 75, 23, 8B, 15, 8C, 05, 01, 00, B8, 84, 06, 01, 00, C1, E8, 08, 33, 02, 25, FF, FF, 00, 00, A3, 84, 06, 01, 00, 75, 07, 8B, C1, A3, 84, 06, 01, 00, F7, D0, A3, 80, 06, 01, 00, 5D, E9, 7A, FD, FF, FF, 94, 07, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, AA, 07, 00, 00, 8C, 05, 00, 00, 88, 07, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, E4, 07, 00, 00, 80, 05, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.9559

Code size:
512 Bytes (512 bytes)

Driver
Display name:
ncvhook

Type:
Kernel device driver (KernelDriver)

Group:
Video


Scan ncvhook.sys - Powered by Reason Core Security