processmon.sys

Wuhan os-easy technology co., ltd

It runs as a Windows kernel mode device driver named “processmon”.
Publisher:
Wuhan os-easy technology co., ltd  (signed and verified)

MD5:
3af9f766e50e37b73a9f9bf0c0f37770

SHA-1:
fa93b9a1e856bc35818f7c95111350ca620a02b7

SHA-256:
9e536ec0ec110f653496e1881172facd233ca7e65fa8f4a49bb8e9e9b916d8e3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/3/2024 12:05:30 AM UTC  (today)

File size:
11 KB (11,312 bytes)

File type:
Driver (Win32 SYS)

Common path:
C:\Program Files\oseasy\lgclient\processmon.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/9/2009 8:00:00 AM

Valid to:
11/9/2010 7:59:59 AM

Subject:
CN="Wuhan os-easy technology co., ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Wuhan os-easy technology co., ltd", L=Wuhan, S=Hubei, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6F896768FC8CA1E4D9D3E48C28332683

File PE Metadata
Compilation timestamp:
12/3/2008 1:57:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
6.0

CTPH (ssdeep):
192:fJMWG+zyh/KcOf+0ibhyowJL/8Qpkqs1I5ZgjlAyBsCCyKO+ebCfsWydr:xMWJGytiNYJLu1M6jyKbC0W

Entry address:
0x3BA

Entry point:
55, 8B, EC, 83, EC, 14, 53, 56, 57, 68, 2C, 03, 01, 00, E8, CF, 06, 00, 00, 8B, 1D, 90, 02, 01, 00, 8D, 45, F4, C7, 04, 24, 4C, 03, 01, 00, 50, FF, D3, 8B, 75, 08, 8D, 45, FC, 50, 6A, 00, 6A, 00, 8D, 45, F4, 6A, 22, 50, 6A, 30, 56, FF, 15, 8C, 02, 01, 00, 85, C0, 0F, 8C, CC, 00, 00, 00, 8B, 45, FC, 6A, 0C, 59, 8B, 78, 28, 33, C0, 89, 3D, 44, 0C, 01, 00, F3, AB, A1, 44, 0C, 01, 00, 80, 60, 1D, 00, A1, 44, 0C, 01, 00, 80, 60, 1C, 00, A1, 44, 0C, 01, 00, 83, 60, 18, 00, A1, 44, 0C, 01, 00, C7, 40, 20, 80, 0F...
 
[+]

Entropy:
6.9680

Developed / compiled with:
Microsoft Visual C++

Code size:
3.3 KB (3,392 bytes)

Driver
Display name:
processmon

Type:
Kernel device driver (KernelDriver)


Scan processmon.sys - Powered by Reason Core Security