psprotect.sys

Hangzhou Shunwang Technology Co.,Ltd

It runs as a Windows kernel mode device driver named “psprotect”.
Publisher:
Hangzhou Shunwang Technology Co.,Ltd  (signed and verified)

MD5:
ee6399422709b2cb8588bf2cf6f5c1ff

SHA-1:
19b2629adb4454828eac675f9c76d97bdde91f85

SHA-256:
bd85830bb4e4f4b3170e031d3b32f05c8e8c70fff79ca3410ccaa00f8fe7148e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 8:29:40 PM UTC  (today)

File size:
35.9 KB (36,800 bytes)

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\psprotect.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/26/2011 11:56:06 PM

Valid to:
6/26/2014 11:56:06 PM

Subject:
CN="Hangzhou Shunwang Technology Co.,Ltd", O="Hangzhou Shunwang Technology Co.,Ltd", L=Hangzhou, S=Zhejiang, C=CN

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121C389611C656AF0D3AB84786EC9517946

File PE Metadata
Compilation timestamp:
4/10/2014 5:12:31 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
384:1jxNovlhG4U22rmbWDb+7QlLrjA9FUrfCJKHLmuvvzDVzkJzBPAh2n2KtPLu9HY+:1Ncm22rNzXjAX8IK1feJzBYh22vh

Entry address:
0x6B3E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 9A, A5, FF, FF, CC, CC, 9C, 6B, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 0C, 72, 00, 00, 90, 5C, 00, 00, 8C, 6B, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 54, 72, 00, 00, 80, 5C, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 2E, 72, 00, 00, 1A, 72, 00, 00, 46, 72, 00, 00, 00, 00, 00, 00, FA, 6C, 00, 00, 14, 6D, 00, 00, 1E, 6D, 00, 00, 38, 6D, 00, 00, 42, 6D, 00, 00, 5A, 6D, 00, 00, 66, 6D, 00, 00, 7A, 6D, 00, 00, 9A, 6D...
 
[+]

Entropy:
6.6050

Code size:
23.9 KB (24,448 bytes)

Driver
Display name:
psprotect

Type:
Kernel device driver (KernelDriver)


Scan psprotect.sys - Powered by Reason Core Security