nwlwf.sys

PCAUSA Sample NDIS Filters

HFN, Inc.

Publisher:
Printing Communications Assoc., Inc. (PCAUSA)  (signed by HFN, Inc.)

Product:
PCAUSA Sample NDIS Filters

Description:
PCAUSA Sample IP Redirector Filter (NDIS6)

Version:
4.00.08.06 - Evaluation Only. Not for commercial redistribution! built by: WinDDK

MD5:
39b7b01a8ce33ae54a3ae4f623a272ae

SHA-1:
7e92878f813f1ddfe430cca126da785fe8b66859

SHA-256:
6ec2048d78515ab6897869b88c70648774af8a4f6a7d77077fa964ae7daa43df

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/3/2024 7:16:46 AM UTC  (today)

File size:
55.3 KB (56,632 bytes)

Product version:
4.00.08.06 - Evaluation Only. Not for commercial redistribution!

Copyright:
Copyright © 2005-2013 PCAUSA

Original file name:
PCAREDIR.SYS

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Program Files\nanoheal\client\nwlwf.sys

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
2/2/2016 5:30:00 AM

Valid to:
2/8/2017 5:30:00 PM

Subject:
CN="HFN, Inc.", O="HFN, Inc.", L=San Jose, S=California, C=US

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
016B8E96EB20B3E9A3D13BF99B5C71C3

File PE Metadata
Compilation timestamp:
4/22/2016 2:00:25 PM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
768:cxPcHc0phYcD1gKS8ytznaIuM87fEWmrQV0osQW6GlyEFKQlv+qWnRyBKgV0d:W2DforHgVM70EAQlv+qWnknu

Entry address:
0xD400

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, EA, FB, FF, FF, CC, CC, 4E, 00, 57, 00, 4C, 00, 57, 00, 46, 00, 00, 00, CC, CC, CC, CC, 4E, 00, 61, 00, 6E, 00, 6F, 00, 68, 00, 65, 00, 61, 00, 6C, 00, 20, 00, 46, 00, 69, 00, 6C, 00, 74, 00, 65, 00, 72, 00, 00, 00, 7B, 00, 30, 00, 46, 00, 34, 00, 43, 00, 46, 00, 37, 00, 44, 00, 32, 00, 2D, 00, 37, 00, 41, 00, 42, 00, 45, 00, 2D, 00, 34, 00, 30, 00, 38, 00, 64, 00, 2D, 00, 42, 00, 38, 00, 45, 00, 42, 00...
 
[+]

Entropy:
6.3359

Code size:
38.5 KB (39,424 bytes)

The file nwlwf.sys has been discovered within the following programs.

BASK Client  by Bask HelpDesk
www.bask.com
About 1% of users remove it
Bask HelpDesk  by Bask HelpDesk
About 8% of users remove it
Nanoheal Client  by Nanoheal
nanoheal.com
About 7% of users remove it
Resolv Client  by Resolv
resolv.com
About 1% of users remove it
 
Powered by Should I Remove It?

Scan nwlwf.sys - Powered by Reason Core Security