niprobemem64.sys

Network Instruments, LLC

Publisher:
Network Instruments LLC  (signed by Network Instruments, LLC)

Description:
NiProbeMem for Observer Device Driver

Version:
11.0.0.0

MD5:
a39f15dc4ca7381ec8877e02a67eea95

SHA-1:
4eed62f11994fbac3d497028404c95cc1241817b

SHA-256:
aa414771b33aa9a301667ab1f74bde4ce6d488ee7342ba8d8d35949edfa31d14

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/7/2024 6:58:19 PM UTC  (today)

File size:
43.8 KB (44,808 bytes)

Product version:
11.0.0.0

Copyright:
Copyright © 1994-2005 Network Instruments LLC. All rights reserved.

Original file name:
NiProbMem.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Program Files\observer\niprobemem64.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/30/2006 6:00:00 PM

Valid to:
10/30/2008 5:59:59 PM

Subject:
CN="Network Instruments, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Network Instruments, LLC", S=Minnesota, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1453B5AB3656CFF121FCD195595BE5D5

File PE Metadata
Compilation timestamp:
3/12/2007 5:05:22 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
768:gfiu/4s4h3vMpNKs3UWMafHWi9muCnVTx7ce3ufrEZM5J7KmbL3ebVIm5:gfimjfMafHWi9muCnVTx7hWrEa5J7K86

Entry address:
0x41F0

Entry point:
48, 89, 5C, 24, 08, 57, 48, 83, EC, 60, 48, 8B, FA, 48, 8B, D9, 4C, 8D, 05, C9, DF, FF, FF, BA, 03, 00, 00, 00, B9, 00, 01, 00, 00, E8, DA, EF, FF, FF, 4C, 8D, 1D, A3, DF, FF, FF, 4C, 8D, 0D, 8C, DF, FF, FF, 4C, 8D, 05, 6D, DF, FF, FF, BA, 04, 00, 00, 00, B9, 00, 01, 00, 00, 4C, 89, 5C, 24, 20, E8, B1, EF, FF, FF, 45, 33, DB, 4C, 89, 1D, E7, 50, 00, 00, 4C, 89, 1D, E8, 50, 00, 00, 0F, B7, 07, 66, 89, 05, D6, 50, 00, 00, 0F, B7, 07, 41, 8D, 4B, 01, 66, 05, 02, 00, 41, B8, 4E, 69, 50, 72, 0F, B7, D0, 66, 89...
 
[+]

Entropy:
5.9552

Code size:
29.5 KB (30,208 bytes)

Scan niprobemem64.sys - Powered by Reason Core Security