prl_memdev.sys

Parallels IP Holdings GmbH

It runs as a Windows kernel mode device driver named “prl_memdev”.
Publisher:
Parallels IP Holdings GmbH  (signed and verified)

MD5:
35f957229ef193c19a78011b5096c7cf

SHA-1:
1618a74182402cfe8e29a4299a1e878e5d937a6e

SHA-256:
23bfb55f76d6cd4bd6d429e0f7fd2479100cea2ddc86c354a026cb0b4cb79745

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/3/2024 9:55:14 PM UTC  (today)

File size:
27.7 KB (28,352 bytes)

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\prl_memdev.sys

Digital Signature
Authority:
Symantec Corporation

Valid from:
6/25/2015 2:00:00 AM

Valid to:
6/25/2018 1:59:59 AM

Subject:
CN=Parallels IP Holdings GmbH, O=Parallels IP Holdings GmbH, L=Schaffhausen, S=Schaffhausen, C=CH, SERIALNUMBER=CHE-195.113.732, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=CH

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA - G2, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
758180AD60C66822665E4FA853A37F48

File PE Metadata
Compilation timestamp:
1/18/2017 10:35:37 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

Entry address:
0x503E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, F4, C3, FF, FF, CC, CC, A8, 50, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, E0, 54, 00, 00, 1C, 30, 00, 00, 8C, 50, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 62, 55, 00, 00, 00, 30, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 3E, 55, 00, 00, 2A, 55, 00, 00, 16, 55, 00, 00, 02, 55, 00, 00, EE, 54, 00, 00, 50, 55, 00, 00, 00, 00, 00, 00, 92, 51, 00, 00, A2, 51, 00, 00, B6, 51, 00, 00, CC, 51, 00, 00, E4, 51, 00, 00, 04, 52...
 
[+]

Code size:
7.5 KB (7,680 bytes)

Driver
Display name:
prl_memdev

Type:
Kernel device driver (KernelDriver)


Scan prl_memdev.sys - Powered by Reason Core Security