VFrtHook.dll

VMFort Guest Additions

VMCraft, Inc

Publisher:
VMCraft Inc  (signed by VMCraft, Inc)

Product:
VMFort Guest Additions

Description:
VmfortHypr Hook Driver

Version:
4.2.4.1481

MD5:
c5d0cef65d93a3da6d9a14b56f54d771

SHA-1:
8cab86b7f0329a56f40ecc82c52d374ce276e5a5

SHA-256:
c2e91ba238831f0f45cb35faca49a34baf27f6582e48503dcf76d1b50628269f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/8/2025 6:24:44 PM UTC  (today)

File size:
50.2 KB (51,408 bytes)

Product version:
4.2.4.1481

Copyright:
Copyright (C) 2009-2014 VMCraft Inc

Original file name:
VFrtHook.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Windows\System32\vfrthook.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/22/2013 9:00:00 AM

Valid to:
10/22/2014 8:59:59 AM

Subject:
CN="VMCraft, Inc", OU=Development, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="VMCraft, Inc", L=Seocho-gu, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4B4AFECBC25B0CD7A6411B27369111A5

File PE Metadata
Compilation timestamp:
6/18/2014 1:38:42 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
768:RhQ6maEePLrkLE44imoh0ym+antEDokdvyEt6BNZ0Cqf:RhSiiJ059p3Et6fRO

Entry address:
0x145F

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 20, 15, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 6A, 00, FF, 15, 14, 80, 00, 10, C3, FF, 15, 18, 80, 00, 10, C2, 04, 00, 8B, FF, 55, 8B, EC, FF, 75, 08, FF, 35, 04, B0, 00, 10, FF, 15, 1C, 80, 00, 10, FF, D0, 5D, C2, 04, 00, A1, 00, B0, 00, 10, C3, 8B, FF, 56, FF, 35, 04, B0, 00, 10, FF, 15, 1C, 80, 00, 10, 8B, F0, 85, F6, 75, 1B, FF, 35, 40, BB, 00, 10, FF, 15, 0C, 80, 00, 10, 8B, F0, 56, FF, 35, 04, B0, 00, 10, FF...
 
[+]

Entropy:
6.3552

Code size:
26 KB (26,624 bytes)

Scan VFrtHook.dll - Powered by Reason Core Security