unlocker.sys

RawDisk

EldoS Corporation

It runs as a Windows kernel mode device driver named “ElRawDisk”.
Publisher:
EldoS Corporation  (signed and verified)

Product:
RawDisk

Description:
RawDisk Driver. Allows write access to files and raw disk sectors for user mode applications in Windows 2000, XP, 2003, Vista, 2008.

Version:
2, 1, 25, 96

MD5:
0df0cd803935ccaa458cdaf75c35b6de

SHA-1:
2a8b6013e41d6405856996ae9c598cc3e8cee8ec

SHA-256:
f535dce812cec4cf618c5b657a8b4e1d6927832876667f017b7e87edf4367f67

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 10:01:57 AM UTC  (today)

File size:
26.4 KB (27,080 bytes)

Product version:
2, 1, 25, 0

Copyright:
Copyright (C) 2007-2010, EldoS Corporation

Original file name:
elrawdsk.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\unlocker.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/11/2010 2:19:26 PM

Valid to:
1/11/2013 2:19:23 PM

Subject:
E=info@eldos.com, CN=EldoS Corporation, O=EldoS Corporation, C=VG

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001261DEC28F7

File PE Metadata
Compilation timestamp:
9/18/2010 12:38:57 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
384:2HTXplN6lCw++FSD+hH/4bzXWQPhuQDCOfTHcQHm87J03+udUb+b1B:EpkxJSO4fHuK97gN3+Vib1B

Entry address:
0x3908

Entry point:
8B, FF, 55, 8B, EC, A1, A0, 0D, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1A, A1, 00, 0B, 01, 00, 8B, 00, 35, A0, 0D, 01, 00, A3, A0, 0D, 01, 00, 75, 07, 8B, C1, A3, A0, 0D, 01, 00, F7, D0, A3, A4, 0D, 01, 00, 5D, E9, C0, FE, FF, FF, 49, 00, 6F, 00, 47, 00, 65, 00, 74, 00, 44, 00, 69, 00, 73, 00, 6B, 00, 44, 00, 65, 00, 76, 00, 69, 00, 63, 00, 65, 00, 4F, 00, 62, 00, 6A, 00, 65, 00, 63, 00, 74, 00, 00, 00, 49, 00, 6F, 00, 47, 00, 65, 00, 74, 00, 4C, 00, 6F, 00, 77, 00, 65, 00, 72, 00, 44, 00...
 
[+]

Code size:
13.8 KB (14,080 bytes)

Driver
Display name:
ElRawDisk

Type:
Kernel device driver (KernelDriver)


Scan unlocker.sys - Powered by Reason Core Security