windrvr9.sys

WinDriver Device Driver (x86)

Talkswitch

It runs as a Windows kernel mode device driver named “WinDriver6”.
Publisher:
Jungo  (signed by Talkswitch)

Product:
WinDriver Device Driver (x86)

Description:
WinDriver Device Driver 9.01

Version:
9.01

MD5:
293d68d2e52bb223d2920841d655c0b3

SHA-1:
6609c05ce1ca0d9053bd88df4cc789ea3a2f486a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 4:23:42 PM UTC  (today)

File size:
188.8 KB (193,304 bytes)

Product version:
9.01

Copyright:
Copyright © Jungo 1997 - 2007

Original file name:
windrvr6.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\windrvr9.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/8/2007 7:00:00 PM

Valid to:
2/9/2010 6:59:59 PM

Subject:
CN=Talkswitch, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Talkswitch, S=Ontario, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0D252EBF7190222724038484FC92C1A7

File PE Metadata
Compilation timestamp:
6/17/2007 6:26:25 AM

OS version:
3.51

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.10

CTPH (ssdeep):
3072:KJuYJ0JeFNOhjP/eT0Q4hHbkh6sMcNseT0c0l8k5qLw:K4VJe/GRQ4OnVSeT0c0l8kQLw

Entry address:
0xDDA0

Entry point:
55, 8B, EC, 56, 68, C0, 04, 40, 00, 68, 70, 06, 40, 00, E8, 83, C4, 01, 00, 8B, 45, 0C, 8B, 75, 08, 83, C4, 08, 50, E8, 0E, FC, FF, FF, 85, C0, 75, 50, 8B, 4E, 18, B8, F0, D5, 40, 00, 89, 46, 38, 89, 46, 40, 89, 46, 70, 89, 86, 80, 00, 00, 00, B8, 10, 49, 42, 00, 89, 46, 44, 89, 46, 48, C7, 46, 34, F0, BE, 40, 00, C7, 41, 04, 10, DB, 40, 00, C7, 86, 90, 00, 00, 00, 70, 0D, 42, 00, C7, 86, A4, 00, 00, 00, D0, 2C, 42, 00, C7, 86, 94, 00, 00, 00, 70, 0F, 42, 00, 33, C0, 5E, 5D, C2, 08, 00, CC, CC, CC, CC, CC...
 
[+]

Entropy:
6.5932

Developed / compiled with:
Microsoft Visual C++

Code size:
168.7 KB (172,704 bytes)

Driver
Display name:
WinDriver6

Type:
Kernel device driver (KernelDriver)


Scan windrvr9.sys - Powered by Reason Core Security