RAMDriv.sys

MSI RAMDrive

Christiaan Ghijselinck

It runs as a Windows kernel mode device driver named “MSI RAMDrive”.
Publisher:
Micro-Star Int'l Co., Ltd.  (signed by Christiaan Ghijselinck)

Product:
MSI RAMDrive

Description:
RAMDisk Driver (x86)

Version:
5,3,2,14 Thu Dec 27 19:19:14 2012

MD5:
623b832482e4890979e62a9555284619

SHA-1:
62b48d43d99334227f7af10a8a1be887cbc62739

SHA-256:
c860e7424f9485298944268c693697de400cb009e4389b4cf6398d45530d3988

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/9/2024 2:01:00 PM UTC  (today)

File size:
70.6 KB (72,312 bytes)

Product version:
5,3,2,14

Copyright:
Copyright (C) Qualitative Software [QSoft]

Original file name:
RAMDriv.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\ramdriv.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
2/7/2012 8:09:01 AM

Valid to:
2/7/2015 8:09:01 AM

Subject:
CN=Christiaan Ghijselinck, C=BE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121153DBF8E6D56FAE09F2EFFCBFD7B41D7

File PE Metadata
Compilation timestamp:
12/27/2012 10:19:26 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
1536:qmimzmuIrPXijrD4e2RThaTe0Flk0YlzlSzr66in2Qirs:qmiMmtXeeRlaa0Fu/lz8/wn2js

Entry address:
0xEB3C

Entry point:
8B, FF, 55, 8B, EC, A1, 38, 9E, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1A, A1, 3C, 6E, 01, 00, 8B, 00, 35, 38, 9E, 01, 00, A3, 38, 9E, 01, 00, 75, 07, 8B, C1, A3, 38, 9E, 01, 00, F7, D0, A3, 3C, 9E, 01, 00, 5D, E9, 0C, FE, FF, FF, CC, CC, C4, EB, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FA, F3, 00, 00, 0C, 6D, 00, 00, B8, EB, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 30, F4, 00, 00, 00, 6D, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 08, F4, 00, 00...
 
[+]

Entropy:
6.7217

Code size:
47.6 KB (48,768 bytes)

Driver
Display name:
MSI RAMDrive

Service name:
RAMDriv

Type:
Kernel device driver (KernelDriver)


Scan RAMDriv.sys - Powered by Reason Core Security