vrclerk.sys

VR Filter for Windows 2K/XP/Vista/7

Hauri, Inc

Publisher:
Hauri, Inc.  (signed by Hauri, Inc)

Product:
VR Filter for Windows 2K/XP/Vista/7

Description:
Virobot log driver

Version:
2010,02,23,0 built by: WinDDK

MD5:
c607f3c565b2ee1e88361120bf61d858

SHA-1:
e4c8558c19a1b77d44c17c82e58e1a832be992ef

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 4:58:54 PM UTC  (today)

File size:
11.9 KB (12,176 bytes)

Product version:
2010,02,23,0

Copyright:
Copyright (C) Hauri, Inc. 1998-2009. All Rights Reserved.

Original file name:
Module Name : VrClerk.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Program Files\hauri\common\base\vrclerk.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/11/2009 7:00:00 PM

Valid to:
6/12/2010 6:59:59 PM

Subject:
CN="Hauri, Inc", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Hauri, Inc", L=Jongno-gu, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0AE19403B4A6D6F9F816BFAA465E44EA

File PE Metadata
Compilation timestamp:
5/7/2010 2:26:38 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
192:4napvZJVbKyA7u8GaSiyowJL/Zq6o+ebCfvQpkqs1I5ZgjlRzOxE:4apvZJVKyA7lGoYJLp+bCL1M6jmxE

Entry address:
0xE85

Entry point:
8B, FF, 55, 8B, EC, A1, 00, 0D, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1A, A1, 18, 0C, 01, 00, 8B, 00, 35, 00, 0D, 01, 00, A3, 00, 0D, 01, 00, 75, 07, 8B, C1, A3, 00, 0D, 01, 00, F7, D0, A3, 04, 0D, 01, 00, 5D, E9, 4D, FC, FF, FF, CC, EC, 0E, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 96, 0F, 00, 00, 00, 0C, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 10, 0F, 00, 00, 20, 0F, 00, 00, 3C, 0F, 00, 00, 54, 0F, 00, 00, 5E, 0F, 00, 00, 6A, 0F, 00, 00, 78...
 
[+]

Entropy:
6.4846

Code size:
2.3 KB (2,304 bytes)

Scan vrclerk.sys - Powered by Reason Core Security