netpeeker.sys

NetPeeker

eMing Software Inc.

It runs as a Windows kernel mode device driver named “NetPeeker”.
Publisher:
eMing Software Inc.  (signed and verified)

Product:
NetPeeker

Description:
NetPeeker Kernel Driver

Version:
3.20.0.0

MD5:
f0c691d381922663131b751d3a37410c

SHA-1:
55ad2b794b214560fef211e26814fd645bef7d04

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 12:54:07 AM UTC  (today)

File size:
259.9 KB (266,184 bytes)

Product version:
3.20.0.0

Copyright:
Copyright© 2002-2010 eMing Software Inc.

Original file name:
NetPeeker32.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\netpeeker.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
5/2/2010 12:23:31 AM

Valid to:
5/2/2013 12:23:27 AM

Subject:
CN=eMing Software Inc., O=eMing Software Inc., L=Irvine, S=CA, C=US

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012855F725CB

File PE Metadata
Compilation timestamp:
8/28/2010 10:58:23 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.10

CTPH (ssdeep):
6144:GQPK+DzH2BB+IGPXR/qKALhPwjZ1APuu2Y2PO3l5IFN8gqmHA:7PK+DzH2BB+IGPXR/qKALhPwjZ1APuu9

Entry address:
0x362A2

Entry point:
55, 8B, EC, 51, 51, C7, 45, FC, 82, 01, 00, C0, FF, 75, 0C, FF, 75, 08, E8, 47, FD, FF, FF, 89, 45, FC, 83, 7D, FC, 00, 0F, 85, 56, 01, 00, 00, 8B, 45, 08, 83, C0, 38, 89, 45, F8, 8B, 45, F8, C7, 40, 6C, 2B, CF, 02, 00, 8B, 45, F8, 8B, 4D, F8, 8B, 49, 6C, 89, 48, 5C, 8B, 45, F8, 8B, 4D, F8, 8B, 49, 5C, 89, 48, 58, 8B, 45, F8, 8B, 4D, F8, 8B, 49, 58, 89, 48, 68, 8B, 45, F8, 8B, 4D, F8, 8B, 49, 68, 89, 48, 64, 8B, 45, F8, 8B, 4D, F8, 8B, 49, 64, 89, 48, 60, 8B, 45, F8, 8B, 4D, F8, 8B, 49, 60, 89, 48, 54, 8B...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
211.5 KB (216,576 bytes)

Driver
Display name:
NetPeeker

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI

Depends on:
Tcpip


Scan netpeeker.sys - Powered by Reason Core Security