winhadnt64.dll

OCular Agent

T.E.C Solutions (G.Z.)Limited

Publisher:
TEC Solutions Limited.  (signed by T.E.C Solutions (G.Z.)Limited)

Product:
OCular Agent

Description:
winhadnt (X64)

Version:
3.22.2916.0

MD5:
89dcec416dfda98d0bb5bb0257d7dabe

SHA-1:
7ecfb82c8ebf22757a9e92eb361bd937d46c5a70

SHA-256:
b0104da2f6a16b310d1646939a4e04c84745daa473e0952936a7e8c3f27fceb6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 6:11:20 PM UTC  (today)

File size:
2.8 MB (2,934,112 bytes)

Product version:
3.22.2916.0

Copyright:
Copyright 2001-2007, TEC Solutions Limited.

Trademarks:
OCular

Original file name:
winhadnt.dll

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\Windows\System32\winhadnt64.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/13/2010 8:00:00 AM

Valid to:
8/13/2013 7:59:59 AM

Subject:
CN=T.E.C Solutions (G.Z.)Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=T.E.C Solutions (G.Z.)Limited, L=Guangzhou, S=Guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
56F51B61D97DB28CDFFDE6BA2D15904A

File PE Metadata
Compilation timestamp:
12/15/2011 5:20:12 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:tXtHkyi3XQjKvNNTZnuJCh0g6KiB/Y7zFYrlrJCmivC9VQEJERze4:rk+juEJChm7ivCnQES

Entry address:
0x782E0

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, FF, 3A, 01, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, A7, FE, FF, FF, CC, CC, CC, 40, 53, 48, 83, EC, 20, 48, 8B, D9, 0F, B6, 09, E8, 7F, 3D, 01, 00, 85, C0, 74, 0B, 80, 7B, 01, 00, B8, 02, 00, 00, 00, 75, 05, B8, 01, 00, 00, 00, 48, 98, 48, 83, C4, 20, 5B, C3, CC, CC, CC, 40, 53, 48, 83, EC, 20, 48, 8B, D9, 0F, B6, 09, E8, 67, 3D, 01...
 
[+]

Entropy:
5.4067

Code size:
1.5 MB (1,534,976 bytes)

Scan winhadnt64.dll - Powered by Reason Core Security