zsport.sys

Vasily Tarasov

It runs as a Windows kernel mode device driver named “zonescreen”.
Publisher:
ZoneOS  (signed by Vasily Tarasov)

Product:
ZoneOS

Description:
ZoneScreen video miniport driver

Version:
1.0.1.0

MD5:
249d76f329e343e4409ffec3627e81a7

SHA-1:
5e0de1c5d3121d06a227c6f9ef34bbf0cd9cfcff

SHA-256:
a5de01c27e5cf3e78e7f0b4836598340684995a14bc0279412f14ba2067e9399

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 10:15:11 AM UTC  (today)

File size:
10.2 KB (10,488 bytes)

Product version:
1.1.12.0

Copyright:
(C) Vasily Tarasov. All rights reserved.

Original file name:
zsport.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\zsport.sys

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
9/23/2008 2:00:00 AM

Valid to:
9/24/2011 1:59:59 AM

Subject:
CN=Vasily Tarasov, O=Vasily Tarasov, STREET=Mamina 21b-25, L=Cheluabinsk, S=Russian Federation, PostalCode=454077, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00D77C65A9FF82BD0485206987045BC417

File PE Metadata
Compilation timestamp:
10/10/2010 6:59:28 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

Entry address:
0x122E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 48, FF, FF, FF, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 53, 56, 8B, 35, 1C, 05, 01, 00, 57, FF, 75, 08, 33, C0, 66, A3, 98, 0A, 01, 00, BB, 00, 01, 00, 00, 8B, C3, BF, 98, 0A, 01, 00, 57, 66, A3, 9A, 0A, 01, 00, C7, 05, 9C, 0A, 01, 00, 88, 06, 01, 00, FF, D6, 68, 94, 05, 01, 00, 57, 8B, 3D, 18, 05, 01, 00, FF, D7, FF, 75, 08, 66, 89, 1D, 92, 0A, 01, 00, 33, C0, BB, 90, 0A, 01, 00, 53, 66, A3, 90, 0A, 01, 00, C7, 05, 94, 0A, 01, 00, 88, 08, 01, 00, FF, D6, 68...
 
[+]

Entropy:
5.8329

Code size:
2.8 KB (2,816 bytes)

Driver
Display name:
zonescreen

Type:
Kernel device driver (KernelDriver)

Group:
Video


Scan zsport.sys - Powered by Reason Core Security