ppa_x64.sys

NGO

It runs as a Windows 64-bit kernel mode device driver named “PhyMem”.
Publisher:
NGO  (signed and verified)

MD5:
6cc2ac7172f4aa215db3fa3d5db0f90e

SHA-1:
e503c4af683db8ba66ed069417aab9caac175817

SHA-256:
6ba96ec0f1ca97b315211685e46720e3b78c642604414f2cb3c66a555b4ea23e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 10:25:38 PM UTC  (today)

File size:
8.5 KB (8,704 bytes)

File type:
Driver (Win64 SYS)

Common path:
C:\Program Files\powerplanassistant\ppa_x64.sys

Digital Signature
Signed by:

Authority:
NGO

Valid from:
12/31/2009 2:11:48 AM

Valid to:
1/1/2040 9:59:59 AM

Subject:
CN=NGO

Issuer:
CN=NGO

Serial number:
C6F13FCD163B5F864A292EAD5BDADAE3

File PE Metadata
Compilation timestamp:
12/29/2009 7:36:19 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
96:jjkkaaIkQBRl1C9fTL86AClOjMddBS2cLV499Cc0litViLqRfNmR:jhhIkQHT4rL8hcdBLaVm9yYbF2

Entry address:
0x11B0

Entry point:
48, 89, 54, 24, 10, 48, 89, 4C, 24, 08, 57, 48, 83, EC, 70, 48, C7, 44, 24, 40, 00, 00, 00, 00, 48, C7, 05, 3D, 20, 00, 00, 00, 00, 00, 00, BA, 50, 00, 00, 00, 33, C9, FF, 15, 60, 0E, 00, 00, 48, 89, 05, 21, 20, 00, 00, 48, 83, 3D, 19, 20, 00, 00, 00, 75, 0A, B8, 9A, 00, 00, C0, E9, 09, 01, 00, 00, 48, 8B, 3D, 06, 20, 00, 00, 33, C0, B9, 50, 00, 00, 00, F3, AA, 48, 8D, 15, EE, 1D, 00, 00, 48, 8D, 4C, 24, 58, FF, 15, 1B, 0E, 00, 00, 48, 8D, 54, 24, 40, 48, 89, 54, 24, 30, C6, 44, 24, 28, 01, C7, 44, 24, 20...
 
[+]

Entropy:
5.2215

Code size:
5 KB (5,120 bytes)

Driver
Display name:
PhyMem

Type:
Kernel device driver (KernelDriver)


Scan ppa_x64.sys - Powered by Reason Core Security