pwdrvio.sys

MT SOLUTION LTD

It runs as a Windows kernel mode device driver named “pwdrvio”.
Publisher:
MT SOLUTION LTD  (signed and verified)

MD5:
21d17dfa4865ca2b558e52ca3996ecee

SHA-1:
8ef5ef439dba636af4983def379897c9fed8fc8c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 3:30:57 PM UTC  (today)

File size:
16.1 KB (16,472 bytes)

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\pwdrvio.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
6/27/2009 12:05:18 AM

Valid to:
6/27/2012 12:05:13 AM

Subject:
E=support@mt-solution.ca, CN=MT SOLUTION LTD, OU=IT, O=MT SOLUTION LTD, L=SURREY, S=BC, C=CA

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001221ECC020D

File PE Metadata
Compilation timestamp:
6/12/2009 8:57:50 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
384:gSkqXXrh7w/irf0fm4Xz18j+TgNE58kOppV:Bnbfsm4XpC+EkOpj

Entry address:
0x5005

Entry point:
8B, FF, 55, 8B, EC, A1, 00, 40, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1A, A1, 70, 30, 01, 00, 8B, 00, 35, 00, 40, 01, 00, A3, 00, 40, 01, 00, 75, 07, 8B, C1, A3, 00, 40, 01, 00, F7, D0, A3, 04, 40, 01, 00, 5D, E9, ED, C6, FF, FF, CC, 6C, 50, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 64, 53, 00, 00, 00, 30, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, EC, 50, 00, 00, F8, 50, 00, 00, 12, 51, 00, 00, 2C, 51, 00, 00, 44, 51, 00, 00, 5C, 51, 00, 00, 6E...
 
[+]

Code size:
7 KB (7,168 bytes)

Driver
Display name:
pwdrvio

Type:
Kernel device driver (KernelDriver)


Scan pwdrvio.sys - Powered by Reason Core Security