SysInfoDetector.sys

SysInfo Detector

Database Harbor Software

It runs as a Windows 64-bit kernel mode device driver named “SysInfoDetector”.
Publisher:
Database Harbor Software  (signed and verified)

Product:
SysInfo Detector

Description:
SysInfo Detector Generic Device Driver

Version:
2, 0, 0, 2

MD5:
e81fd810ac1708e619cfd75900000a46

SHA-1:
96dbd179c8f1ba0d6835f510d3c31064d0233cca

SHA-256:
4a532a88c96bd9175ddcff3a44890709ed809d5113ac56b9fd9352e62fc5d337

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 8:42:38 PM UTC  (today)

File size:
15.8 KB (16,176 bytes)

Product version:
2. 0. 0. 2

Copyright:
Copyright (C) 2010-20011 Database Harbor Software

Original file name:
SysInfoDetector.sys

File type:
Driver (Win64 SYS)

Common path:
C:\Windows\System32\sysinfodetector.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/10/2011 4:00:00 AM

Valid to:
2/4/2014 3:59:59 AM

Subject:
CN=Database Harbor Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Database Harbor Software, L=Ulan-Ude, S=Buryatia, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
506316C6F8A5128D21E61F461FB4A822

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
192:ROEaWJxJIYIpI3IaIzITEq8rSyowJL/cu7RZgjlTr7TxH+vfur9ZCspE+TMIrN7:4EaYJYoPyWEqmSYJLca6jZTxkeMy7

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 12, D4, FF, FF, CC, CC, A0, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 50, 42, 00, 00, 14, 20, 00, 00, 8C, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, AA, 42, 00, 00, 00, 20, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 82, 42, 00, 00, 70, 42, 00, 00, 5E, 42, 00, 00, 96, 42, 00, 00, 00, 00, 00, 00, 54, 41, 00, 00, 66, 41, 00, 00, 84, 41, 00, 00, A2, 41, 00, 00, C0, 41, 00, 00, 3C, 41, 00, 00, EE, 41, 00, 00, 0E, 42...
 
[+]

Driver
Display name:
SysInfoDetector

Type:
Kernel device driver (KernelDriver)


Scan SysInfoDetector.sys - Powered by Reason Core Security