OAdriver.sys

OA Helper Driver

Tall Emu

It runs as a Windows kernel mode device driver named “OADriver”.
Publisher:
Tall Emu Pty Ltd  (signed by Tall Emu)

Product:
OA Helper Driver

Version:
2, 1, 0, 5

MD5:
59b4e8edb08613ee86242abb96bdba12

SHA-1:
8ef1e8bfa305eccc4a66a0f72854b835d09a4c4a

SHA-256:
0bf5d27307729b73a25a0d560cecf95e3bf3b387f08f1606f0cf81ff2b15fb25

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 6:07:37 AM UTC  (today)

File size:
174.2 KB (178,376 bytes)

Product version:
2, 1, 0, 5

Copyright:
Copyright © www.tallemu.com 2006-2008

Original file name:
OAdriver.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\oadriver.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/25/2008 11:55:39 AM

Valid to:
2/25/2010 11:55:39 AM

Subject:
E=support@tallemu.com, CN=Tall Emu, O=Tall Emu, C=AU

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001185185634A

File PE Metadata
Compilation timestamp:
10/1/2008 10:50:00 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
3072:FVtgfnmpRPeP+eXI0GtofvmhxrgxD++H+2XAUG90yttwfXmZRjgpjH6JlUef+OXT:FtnZbdMMTcZQuSJc5k+ne9r3cZGsFV/c

Entry address:
0xE5A0

Entry point:
55, 8B, EC, 6A, FF, 68, 68, 6D, 03, 00, 68, EC, 54, 03, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, C4, D4, 53, 56, 57, 89, 65, E8, 68, 3C, 73, 03, 00, E8, D0, 8C, FF, FF, 83, C4, 04, 83, 7D, 08, 00, 74, 08, 8B, 45, 08, 83, C0, 38, 75, 0A, B8, 01, 00, 00, C0, E9, 67, 15, 00, 00, C7, 45, E0, 00, 00, 00, 00, EB, 09, 8B, 4D, E0, 83, C1, 01, 89, 4D, E0, 83, 7D, E0, 1B, 7D, 10, 8B, 55, E0, 8B, 45, 08, C7, 44, 90, 38, B0, C2, 01, 00, EB, E1, 8B, 4D, 08, C7, 41, 34, 80, DA, 01, 00, C7, 05, 60...
 
[+]

Entropy:
6.5943

Developed / compiled with:
Microsoft Visual C++

Code size:
154.5 KB (158,208 bytes)

Driver
Display name:
OADriver

Service name:
OADevice

Type:
Kernel device driver (KernelDriver)


Scan OAdriver.sys - Powered by Reason Core Security