procexp100.sys

Process Explorer

Mark's Certificate

It runs as a Windows kernel mode device driver named “PROCEXP100”.
Publisher:
Sysinternals - www.sysinternals.com  (signed by Mark's Certificate)

Product:
Process Explorer

Version:
9.30

MD5:
4221c4097b89cdae76e198e63812af98

SHA-1:
179b8fce9125bf1612330d1f478e645c6fc4865c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 1:21:37 AM UTC  (today)

File size:
11.9 KB (12,176 bytes)

Product version:
9.30

Copyright:
Copyright (C) M. Russinovich 1996-2005

Original file name:
procexp.Sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\procexp100.sys

Digital Signature
Authority:
Mark's Certificate

Valid from:
1/1/2005 7:00:00 AM

Valid to:
1/1/2011 7:00:00 AM

Subject:
CN=Mark's Certificate

Issuer:
CN=Mark's Certificate

Serial number:
DBC72CC7C648558741FAE6250666BC73

File PE Metadata
Compilation timestamp:
1/7/2006 12:04:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
6.0

CTPH (ssdeep):
192:xhtTd76HVYPi41PtID8KwpGbjrknUssHlQaRycYkatID6zrClaL6wqMwO:xTTRZ1G4p+knUssHlQ6gyD6zrClaWwnh

Entry address:
0xF02

Entry point:
55, 8B, EC, 81, EC, B0, 00, 00, 00, 53, 56, 57, 6A, 09, 59, BE, 6E, 0E, 00, 08, 8D, 7D, BC, 6A, 0B, F3, A5, 66, A5, 59, BE, 96, 0E, 00, 08, 8D, 7D, 8C, 83, 7D, 0C, 00, F3, A5, 66, A5, 6A, 0F, BE, C6, 0E, 00, 08, 59, 8D, BD, 50, FF, FF, FF, F3, A5, BB, 46, 0D, 00, 08, 75, 2F, 68, 44, 64, 6B, 20, 68, 50, 01, 00, 00, 6A, 00, FF, 15, CC, 02, 00, 08, 8B, F0, 6A, 54, 59, 33, C0, 8B, FE, 81, C6, A8, 00, 00, 00, F3, AB, 6A, 1C, 8D, 7E, 38, 59, 8B, C3, F3, AB, EB, 03, 8B, 75, 08, 8B, 3D, C0, 02, 00, 08, 8D, 45, BC...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
4.7 KB (4,832 bytes)

Driver
Display name:
PROCEXP100

Type:
Kernel device driver (KernelDriver)


Scan procexp100.sys - Powered by Reason Core Security