shieldi64.sys

EAZ SOLUTION, INC.

Publisher:
EAZ SOLUTION, INC.  (signed and verified)

Description:
WINNT/2K/XP/2003 Driver

Version:
8.1.0.0 built by: WinDDK

MD5:
c068127b5cc4e478e10a6cfa7f389d43

SHA-1:
8d4325b89f5620d618e6246c09a6931d465f1031

SHA-256:
ee892d03dc26952af7fb119720bd7e3ed75216e3c4f52a5014ceff71ce7f4c38

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 8:03:48 PM UTC  (today)

File size:
239.8 KB (245,568 bytes)

Product version:
8.1.0.0

Copyright:
Patent pending. All rights reserved.

Original file name:
SYSSHD.sys

File type:
Driver (Win32 SYS)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\system32\drivers\shieldi64.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/26/2007 8:00:00 AM

Valid to:
12/12/2009 7:59:59 AM

Subject:
CN="EAZ SOLUTION, INC.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="EAZ SOLUTION, INC.", L=Richardson, S=Texas, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4BBC38CB734B856861478A94895812E7

File PE Metadata
Compilation timestamp:
3/18/2008 4:30:06 PM

OS version:
5.2

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.10

CTPH (ssdeep):
6144:hLKIh59+oJ+HTmi48t+CUGVPT3+U+K9Bb3vFRLAI8B6i0WeUmLsT782VaU:Bz63NhTP59tfFgtP82sU

Entry address:
0x360B0

Entry point:
00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 03, 00, 00, 00, 04, 00, 00, 00, 0A, E6, 00, B1, 23, E4, 01, B0, A2, E0, 02, 01, 61, 6E, 81, C0, 02, 2C, A1, 2C, A1, 29, A1, 29, A1, 26, A1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 03, 00, 00, 00, 03, 00, 00, 00, 09, E6, 00, B1, 31, E4, 01, B0, B0, EA, 07, B2, B2, 61, BA, 01, 81, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 03, 00, 00, 00, 02, 00, 00, 00, 15, E6, 00, B1...
 
[+]

Entropy:
5.4811

Code size:
208.5 KB (213,504 bytes)

Scan shieldi64.sys - Powered by Reason Core Security