ohi2pzhs.sys

VBA32

VIRUSBLOKADA LTD.

It runs as a Windows kernel mode device driver named “Vba32 Armour Driver”.
Publisher:
VIRUSBLOKADA LTD.  (signed and verified)

Product:
VBA32

Description:
Vba32 AntiRootkit driver

Version:
5.1 built by: WinDDK

MD5:
d1e32eb3a330c6e85c042f87ee5e0590

SHA-1:
0e3ad1a60a0d87e5cdf7fba8ca5e40c8e5cd19c4

SHA-256:
b0469fcb86df64a1e67d24ae10a7b368c29c21a88b1bba6830446442fa6c93f6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 4:29:08 AM UTC  (today)

File size:
68.4 KB (70,024 bytes)

Product version:
3.12

Copyright:
Copyright © 1993-2010 VirusBlokAda Ltd. All rights reserved.

Original file name:
Vba32Arr.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\ohi2pzhs.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/29/2010 4:00:00 AM

Valid to:
1/31/2012 3:59:59 AM

Subject:
CN=VIRUSBLOKADA LTD., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=VIRUSBLOKADA LTD., L=Minsk, S=none, C=BY

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2BEF4F72149367BCC7775D0000909C1D

File PE Metadata
Compilation timestamp:
5/8/2010 3:41:15 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
1536:z/vdHuL2esbVZSQN3pDfs0JgTaBkg2xCfU:xOBsbrx3pLvkWU

Entry address:
0x11006

Entry point:
8B, FF, 55, 8B, EC, 81, EC, B4, 00, 00, 00, 53, 56, 57, 6A, 04, 58, 6A, 08, 66, A3, 20, 04, 02, 00, 58, 6A, 1C, 66, A3, 22, 04, 02, 00, 58, 66, A3, 1E, 04, 02, 00, 6A, 38, 58, 6A, 18, 66, A3, 24, 04, 02, 00, 5E, 6A, 24, 8B, C6, 66, A3, 26, 04, 02, 00, 58, 66, A3, 2A, 04, 02, 00, B8, C4, 00, 00, 00, 66, A3, 12, 04, 02, 00, 83, C0, C4, 66, A3, 0E, 04, 02, 00, BA, B0, 01, 00, 00, 8B, C2, 66, A3, 14, 04, 02, 00, B8, 9C, 00, 00, 00, 66, A3, 16, 04, 02, 00, 83, C0, E4, 6A, 50, 66, A3, 1C, 04, 02, 00, 58, 6A, 60...
 
[+]

Code size:
57.5 KB (58,880 bytes)

Driver
Display name:
Vba32 Armour Driver

Service name:
ohi2pzhs

Type:
Kernel device driver (KernelDriver)


Scan ohi2pzhs.sys - Powered by Reason Core Security