niprobemem.sys

Network Instruments, LLC

It runs as a Windows 64-bit kernel mode device driver named “NiProbeMem”.
Publisher:
Network Instruments LLC  (signed by Network Instruments, LLC)

Description:
NiProbeMem for Observer Device Driver

Version:
16,1,17,0

MD5:
a381b2e7a39e2cff33aee72f2c2a11f6

SHA-1:
548fa5ceb58f2010d793a287f1499d1c895ded41

SHA-256:
748585c1cb048feae4b49f1ba80a8d52865b8f0f7aa387afe80deb61d4038b33

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 4:08:58 AM UTC  (today)

File size:
52.8 KB (54,016 bytes)

Product version:
16,1,17,0

Copyright:
Copyright © 1994-2013 Network Instruments, LLC. All rights reserved.

Original file name:
NiProbMem.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\niprobemem.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/13/2011 2:00:00 AM

Valid to:
10/30/2014 1:59:59 AM

Subject:
CN="Network Instruments, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Network Instruments, LLC", S=Minnesota, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1F687F97C7FDCBFF63F002FA4090B2BF

File PE Metadata
Compilation timestamp:
1/27/2014 2:33:53 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
10.0

CTPH (ssdeep):
768:qSop49op4W5oMkpPkAQEweTwSYJDgEEkIxk3e3SjimOymaN:/DXpP37weTwS854SjimAy

Entry address:
0x5900

Entry point:
48, 89, 5C, 24, 08, 57, 48, 83, EC, 60, 48, 8B, DA, 48, 8B, F9, 4C, 8D, 05, 51, CF, FF, FF, BA, 03, 00, 00, 00, B9, 00, 01, 00, 00, E8, 0A, EF, FF, FF, 4C, 8D, 1D, 2B, CF, FF, FF, 4C, 8D, 0D, 14, CF, FF, FF, 4C, 8D, 05, F5, CE, FF, FF, BA, 04, 00, 00, 00, B9, 00, 01, 00, 00, 4C, 89, 5C, 24, 20, E8, E1, EE, FF, FF, 4C, 8B, 1D, 12, B7, FF, FF, 41, 80, 3B, 00, 74, 2C, 4C, 8D, 05, A5, CE, FF, FF, BA, 01, 00, 00, 00, B9, 00, 01, 00, 00, E8, BE, EE, FF, FF, FF, 15, E8, B6, FF, FF, B8, 9A, 00, 00, C0, 48, 8B, 5C...
 
[+]

Code size:
38 KB (38,912 bytes)

Driver
Display name:
NiProbeMem

Type:
Kernel device driver (KernelDriver)


Scan niprobemem.sys - Powered by Reason Core Security