QIOMem.sys

WDKTestCert 1

It runs as a Windows 64-bit kernel mode device driver named “Generic IO & Memory Access”.
Publisher:
TOSHIBA  (signed by WDKTestCert 1)

Description:
Generic IO & Memory Access

Version:
5.0.0.0

MD5:
43252ab49c9a43d22aa583c15e96f7b7

SHA-1:
ee37a040b6ec7882b4e240e70da67bc0900fd799

SHA-256:
6abd8d0d541bcf9e257c65122216b1d2ae92cbf8a3a3cb7ce340846e66c449ca

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/21/2024 10:33:37 AM UTC  (today)

File size:
22.2 KB (22,736 bytes)

Product version:
5.0.0.0

Copyright:
Copyright(C) 2009-2016 TOSHIBA. All rights reserved.

Original file name:
QIOMem.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\qiomem.sys

Digital Signature
Signed by:

Authority:
WDKTestCert 1

Valid from:
5/4/2015 8:22:00 PM

Valid to:
5/4/2025 4:00:00 PM

Subject:
CN="WDKTestCert 1,130752733198717037"

Issuer:
CN="WDKTestCert 1,130752733198717037"

Serial number:
1FA194EC05480FAF4587210ED5DADD0E

File PE Metadata
Compilation timestamp:
5/4/2015 9:40:35 PM

OS version:
10.0

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
14.0

CTPH (ssdeep):
384:MO2ignX6jC4LGPKMGH58nthbyFRK72/lBRAWY2MjBo7Z:4vQM18DrRAOMjO7Z

Entry address:
0x7090

Entry point:
48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8B, DA, 48, 8B, F9, E8, 17, 00, 00, 00, 48, 8B, D3, 48, 8B, CF, 48, 8B, 5C, 24, 30, 48, 83, C4, 20, 5F, E9, 46, FF, FF, FF, CC, CC, 48, 8B, 05, 45, CF, FF, FF, 48, 85, C0, 74, 1A, 48, B9, 32, A2, DF, 2D, 99, 2B, 00, 00, 48, 3B, C1, 74, 0B, 48, F7, D0, 48, 89, 05, 1F, CF, FF, FF, C3, B9, 06, 00, 00, 00, CD, 29, CC, CC, CC, 18, 71, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, AC, 74, 00, 00, 00, 30, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.4194

Code size:
7.5 KB (7,680 bytes)

Driver
Display name:
Generic IO & Memory Access

Service name:
QIOMem

Type:
Kernel device driver (KernelDriver)


Scan QIOMem.sys - Powered by Reason Core Security