5ad8a3b6-6d20-4c95-8fa7-9a507167ba3c

netfilter2.sys :inline

Description

Confirmed vulnerable driver from Microsoft Block List

  • UUID: 5ad8a3b6-6d20-4c95-8fa7-9a507167ba3c
  • Created: 2023-07-22
  • Author: Michael Haag
  • Acknowledgement: |

Download

Use CasePrivilegesOperating System
Elevate privilegeskernelWindows

Detections

YARA 🏹

Expand

Sigma 🛡️

Expand

Names

detects loading using name only

Hashes

detects loading using hashes only

Sysmon 🔎

Expand

Block

on hashes

Alert

on hashes

Resources


  • https://gist.github.com/mgraeber-rc/1bde6a2a83237f17b463d051d32e802c

  • CVE

  • Known Vulnerable Samples

    PropertyValue
    Filename
    Creation Timestamp2019-05-24 14:59:14
    MD50c1a4b584106cca4edce5d04c89eef67
    SHA1916fb0eb154d7db937cbf91078ad7925cc9f5698
    SHA256f1718a005232d1261894b798a60c73d971416359b70d0e545d7e7a40ed742b71
    Authentihash MD5b2d0111f81238f6e6e6513cf7625a19f
    Authentihash SHA18a50e81d6e6c45410bf13f95b1a67cada8c82221
    Authentihash SHA2565b9623da9ba8e5c80c49473f40ffe7ad315dcadffc3230afdc9d9226d60a715a
    RichPEHeaderHash MD55b7b715c6161f0c21973651546138a54
    RichPEHeaderHash SHA11d8e5160350b5cfcef52a4f49404c7302e5b5abf
    RichPEHeaderHash SHA256737a8bf726624e5e3f3babfce98b9060b7d72412c0bdd28ca3dec0b9d2241817
    Company宏图无忧
    DescriptionWYJSQ WFP Driver (WPP)
    Product无忧加速器
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 09450b8f73ea43e39d2cdd56049dbe40
    FieldValue
    ToBeSigned (TBS) MD5bcfecc67375f580ac6eadd789860b1f8
    ToBeSigned (TBS) SHA13fa9cf13a1816a6e358bb1ca12e050662bc2e178
    ToBeSigned (TBS) SHA256fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df
    SubjectC=CN, ST=, L=, O=, CN=
    ValidFrom2019-06-27 00:00:00
    ValidTo2020-06-30 12:00:00
    Signature03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber09450b8f73ea43e39d2cdd56049dbe40
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 02c4d1e58a4a680c568da3047e7e4d5f
    FieldValue
    ToBeSigned (TBS) MD5829995f702421dea833a24fb2c7f4442
    ToBeSigned (TBS) SHA11d7e838accd498c2e5ba9373af819ec097bb955c
    ToBeSigned (TBS) SHA25692914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1
    ValidFrom2011-02-11 12:00:00
    ValidTo2026-02-10 12:00:00
    Signature49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber02c4d1e58a4a680c568da3047e7e4d5f
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • NDIS.SYS
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • FwpmTransactionCommit0
    • FwpmTransactionAbort0
    • FwpmProviderAdd0
    • FwpmProviderContextDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmSubLayerEnum0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmCalloutAdd0
    • FwpmFilterAdd0
    • FwpsFlowAbort0
    • FwpsInjectionHandleCreate0
    • FwpsInjectionHandleDestroy0
    • FwpsAllocateNetBufferAndNetBufferList0
    • FwpsFreeNetBufferList0
    • FwpmTransactionBegin0
    • FwpsInjectNetworkSendAsync0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsInjectTransportSendAsync0
    • FwpsInjectTransportReceiveAsync0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsStreamInjectAsync0
    • FwpsCopyStreamDataToBuffer0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • FwpmBfeStateUnsubscribeChanges0
    • FwpsFlowRemoveContext0
    • FwpsCompleteClassify0
    • FwpsRedirectHandleDestroy0
    • FwpsCloneStreamData0
    • FwpsDiscardClonedStreamData0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpmFreeMemory0
    • FwpsRedirectHandleCreate0
    • FwpsQueryPacketInjectionState0
    • FwpsApplyModifiedLayerData0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsReleaseClassifyHandle0
    • FwpsFlowAssociateContext0
    • FwpsAcquireClassifyHandle0
    • FwpsPendClassify0
    • FwpsCalloutUnregisterByKey0
    • FwpsCalloutRegister1
    • FwpsFreeCloneNetBufferList0
    • NdisAllocateNetBufferListPool
    • NdisWaitEvent
    • NdisInitializeEvent
    • NdisFreeGenericObject
    • NdisAllocateGenericObject
    • NdisGetDataBuffer
    • NdisAdvanceNetBufferDataStart
    • NdisRetreatNetBufferDataStart
    • NdisFreeNetBufferListPool
    • memset
    • RtlInitUnicodeString
    • MmGetSystemRoutineAddress
    • RtlAppendUnicodeToString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeInitializeEvent
    • KeSetEvent
    • KeWaitForSingleObject
    • KeInitializeSpinLock
    • ExFreePoolWithTag
    • InterlockedPopEntrySList
    • InterlockedPushEntrySList
    • ExInitializeNPagedLookasideList
    • ExDeleteNPagedLookasideList
    • MmBuildMdlForNonPagedPool
    • MmMapLockedPagesSpecifyCache
    • MmUnmapLockedPages
    • MmAllocatePagesForMdl
    • MmFreePagesFromMdl
    • PsCreateSystemThread
    • PsTerminateSystemThread
    • IoAllocateMdl
    • IofCompleteRequest
    • IoCreateDevice
    • IoCreateSymbolicLink
    • IoDeleteDevice
    • IoDeleteSymbolicLink
    • IoFreeMdl
    • IoReleaseCancelSpinLock
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwClose
    • ZwOpenKey
    • ZwQueryValueKey
    • PsGetCurrentProcessId
    • ZwSetInformationThread
    • RtlLengthSid
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwSetSecurityObject
    • SeExports
    • KeQuerySystemTime
    • _allmul
    • _aulldiv
    • _aullrem
    • RtlUnwind
    • memcpy
    • swprintf_s
    • ExUuidCreate
    • ExAllocatePoolWithTag
    • KeReleaseInStackQueuedSpinLock
    • KeGetCurrentIrql
    • KeAcquireInStackQueuedSpinLock

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2020-09-15 00:54:41
    MD5724c7d404a7c182084c6f6c2d20e9e05
    SHA1ac056610db0b5f616aafacdc565d9b9f95870e60
    SHA25671701c5c569ef67391c995a12b21ca06935b7799ed211d978f7877115c58dce0
    Authentihash MD53361957860d2b65c0368778ca088946f
    Authentihash SHA16a784d45517142c11d5cca3ff9956b2ed6eaf4c9
    Authentihash SHA256e94e8a87459db56837d1c58f9854794aa99f36566a9ded9b398be9d4d3a2c2af
    RichPEHeaderHash MD5c646eed94ec9e75c1a5498d3642cdab3
    RichPEHeaderHash SHA10d0761641e424cc895ba76723784427fcf297f4a
    RichPEHeaderHash SHA2567cecb42d3d4ae8649f3b4714fbab29c4cef8e24a48b0eea2537824fc40f4ea7f
    CompanyWindows (R) Win 7 DDK provider
    DescriptionNetFilter SDK WFP Driver (WPP)
    ProductWindows (R) Win 7 DDK driver
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 330000003a6ae333708fda7a7b00000000003a
    FieldValue
    ToBeSigned (TBS) MD56f5d716e7151f1c173396adb7213359e
    ToBeSigned (TBS) SHA1100610baae90027e9844a8e9c4d489fe122ecd9c
    ToBeSigned (TBS) SHA256677d532777cee24be88442efec75e9640e80ef57d8e1246396459a1a04be733f
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher
    ValidFrom2020-03-11 17:31:14
    ValidTo2021-03-05 17:31:14
    Signature7dfc7c353c4c04d9d06066e1ca8584637192eb15d1d6e7c5521b0d819d615fb56524985d30535b0573fb8e0d13173d51b27bd23b9a2052738891d67ed360766452b62c4566eb20c90f018229a8e951bf58df5a7d731c1e51217f471d470979f04e900920bfc8715122b331d82f68f73ebf3de36e09d18fbfed2f3c29190a41baafbca0025bf4e36310a04cb8e61c32fda677820aa693a7f5e69d3c3abdb495b12bb8b6d10f65d44fae945d9b0fcf695d4711fc9e1c0ddb1f569c13093e16c389f748d8fe60e8685f02357464564761db4cece391baa742f3ad3bcfa26e01975966ca41939c832bf1147bec870162ce042fd0cf10d048181ec573d317f2c5de21512f13b24de9bac9bb83fc2ceb4f6f766536fe38c03ede1f8b0a3b8828e8d914d73d0a17699ab20264a27a36e0f77c5144cf470bf44d2296290e345bd25c0bc6a08dd963ec39ce0e500599751c652dc20e9906c1ce76c1d86c09058ae8defb3d7b93b68a34ca83a981a30c2403723f7e5c664b1e951050002ad32e976db221c2d8c660047dc6acfe0da16d44c6372a5cd04b016a35193f841b903ba87e2d6e416a2c59469af9f16e249bb891f21ec22f2db0a84a48d7a9e43d2f7e3bdd016d600f57daf21829885ec035287ab332c32738f5e26c6d2502b2f044afb1e048c85c7c9baf76747de14ecdeca3c7481796a741672a047f89dafe2c12c01982a026c4
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber330000003a6ae333708fda7a7b00000000003a
    Version3
    Certificate 330000000d690d5d7893d076df00000000000d
    FieldValue
    ToBeSigned (TBS) MD583f69422963f11c3c340b81712eef319
    ToBeSigned (TBS) SHA10c5e5f24590b53bc291e28583acb78e5adc95601
    ToBeSigned (TBS) SHA256d8be9e4d9074088ef818bc6f6fb64955e90378b2754155126feebbbd969cf0ae
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2014
    ValidFrom2014-10-15 20:31:27
    ValidTo2029-10-15 20:41:27
    Signature96b5c33b31f27b6ba11f59dd742c3764b1bca093f9f33347e9f95df21d89f4579ee33f10a3595018053b142941b6a70e5b81a2ccbd8442c1c4bed184c2c4bd0c8c47bcbd8886fb5a0896ae2c2fdfbf9366a32b20ca848a6945273f732332936a23e9fffdd918edceffbd6b41738d579cf8b46d499805e6a335a9f07e6e86c06ba8086725afc0998cdba7064d4093188ba959e69914b912178144ac57c3ae8eae947bcb3b8edd7ab4715bba2bc3c7d085234b371277a54a2f7f1ab763b94459ed9230cce47c099212111f52f51e0291a4d7d7e58f8047ff189b7fd19c0671dcf376197790d52a0fbc6c12c4c50c2066f50e2f5093d8cafb7fe556ed09d8a753b1c72a6978dcf05fe74b20b6af63b5e1b15c804e9c7aa91d4df72846782106954d32dd6042e4b61ac4f24636de357302c1b5e55fb92b59457a9243d7c4e963dd368f76c728caa8441be8321a66cde5485c4a0a602b469206609698dcd933d721777f886dac4772daa2466eab64682bd24e98fb35cc7fec3f136d11e5db77edc1c37e1f6a4a14f8b4a721c671866770cdd819a35d1fa09b9a7cc55d4d728e74077fa74d00fcdd682412772a557527cda92c1d8e7c19ee692c9f7425338208db38cc7cc74f6c3a6bc237117872fe55596460333e2edfc42de72cd7fb0a82256fb8d70c84a5e1c4746e2a95329ea0fecdb4188fd33bad32b2b19ab86d0543fbff0d0f
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber330000000d690d5d7893d076df00000000000d
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • NDIS.SYS
    • ntoskrnl.exe

    Imported Functions

    Expand
    • FwpmFreeMemory0
    • FwpmEngineOpen0
    • FwpmEngineClose0
    • FwpmTransactionBegin0
    • FwpmTransactionCommit0
    • FwpmTransactionAbort0
    • FwpmProviderAdd0
    • FwpmProviderContextDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmSubLayerEnum0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmCalloutAdd0
    • FwpmFilterAdd0
    • FwpsFlowAbort0
    • FwpsInjectionHandleCreate0
    • FwpsInjectionHandleDestroy0
    • FwpsRedirectHandleCreate0
    • FwpsFreeNetBufferList0
    • FwpsFreeCloneNetBufferList0
    • FwpsInjectNetworkSendAsync0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsInjectTransportSendAsync0
    • FwpsInjectTransportReceiveAsync0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsStreamInjectAsync0
    • FwpsCopyStreamDataToBuffer0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • FwpmBfeStateUnsubscribeChanges0
    • FwpsFlowRemoveContext0
    • FwpsCompleteClassify0
    • FwpsRedirectHandleDestroy0
    • FwpsCloneStreamData0
    • FwpsDiscardClonedStreamData0
    • FwpsQueryPacketInjectionState0
    • FwpsApplyModifiedLayerData0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsReleaseClassifyHandle0
    • FwpsAcquireClassifyHandle0
    • FwpsFlowAssociateContext0
    • FwpsCalloutUnregisterByKey0
    • FwpsCalloutRegister1
    • FwpsPendClassify0
    • FwpsAllocateNetBufferAndNetBufferList0
    • NdisFreeNetBufferListPool
    • NdisAllocateNetBufferListPool
    • NdisWaitEvent
    • NdisInitializeEvent
    • NdisFreeGenericObject
    • NdisAllocateGenericObject
    • NdisGetDataBuffer
    • NdisAdvanceNetBufferDataStart
    • NdisRetreatNetBufferDataStart
    • KeAcquireInStackQueuedSpinLock
    • KeReleaseInStackQueuedSpinLock
    • ExAllocatePoolWithTag
    • ExUuidCreate
    • swprintf_s
    • RtlInitUnicodeString
    • MmGetSystemRoutineAddress
    • RtlAppendUnicodeToString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeInitializeEvent
    • KeSetEvent
    • KeWaitForSingleObject
    • KeInitializeSpinLock
    • ExFreePoolWithTag
    • ExQueryDepthSList
    • ExpInterlockedPopEntrySList
    • ExpInterlockedPushEntrySList
    • ExInitializeNPagedLookasideList
    • ExDeleteNPagedLookasideList
    • MmBuildMdlForNonPagedPool
    • MmMapLockedPagesSpecifyCache
    • MmUnmapLockedPages
    • MmAllocatePagesForMdl
    • MmFreePagesFromMdl
    • PsCreateSystemThread
    • PsTerminateSystemThread
    • IoAllocateMdl
    • IofCompleteRequest
    • IoCreateDevice
    • IoCreateSymbolicLink
    • IoDeleteDevice
    • IoDeleteSymbolicLink
    • IoFreeMdl
    • IoReleaseCancelSpinLock
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwClose
    • ZwOpenKey
    • ZwQueryValueKey
    • PsGetCurrentProcessId
    • ZwSetInformationThread
    • RtlLengthSid
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwSetSecurityObject
    • __C_specific_handler
    • SeExports
    • RtlGetVersion
    • RtlCompareMemory
    • RtlValidSid

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2020-09-15 00:54:17
    MD5c6dcf97b669be21dffd4e96aecec3066
    SHA106b52ba103412f4ab49fac7129129c10570fd6fd
    SHA25647e35f474f259314c588af35e88561a015801b52db523eb75fc7eccff8b3be4d
    Authentihash MD56d4517e6348130fe55f11bfd630d857f
    Authentihash SHA160a632e4b838731aad553650d6bc8af3d3d80b26
    Authentihash SHA2568168304169a2453c0c3e0a285c2a07d3b3b83433e0342f6b33400c371af86221
    RichPEHeaderHash MD54c93d23c41f384b75bda01c7ace495d8
    RichPEHeaderHash SHA128695a10b02de9e1ce2d2b70c463f5d3bbaeaf4c
    RichPEHeaderHash SHA2564049be109d3e76b72f97f3faab4a4456933bce7ec4593342fd7046ca2bae226e
    CompanyWindows (R) Win 7 DDK provider
    DescriptionNetFilter SDK WFP Driver (WPP)
    ProductWindows (R) Win 7 DDK driver
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 4b51e8986bf2670974fecc6dad020f19
    FieldValue
    ToBeSigned (TBS) MD50538926e1c7f1fcaee6540250d010840
    ToBeSigned (TBS) SHA159887d34eaaa74baf151589daef69b2b6f2d9b55
    ToBeSigned (TBS) SHA256b52255871658ceb663a52576f271ee86d661c2594fc3aa93bbf62ce8a8c77428
    SubjectC=IN, ST=Rajasthan, L=Jaipur, O=SYSTWEAK SOFTWARE PVT. LTD., CN=SYSTWEAK SOFTWARE PVT. LTD.
    ValidFrom2020-07-03 00:00:00
    ValidTo2021-09-01 23:59:59
    Signature658280479fe306aab0994dc8906bc888a766f0a7cdf8b6e0f6008bee7672c4e903d8433af6a9b719a6089420404c164022d367e638da20898cfc10d30970a527a88fbb47ad4c50c44c14028ee1618992c921ac6c2fd07222d6751dba49b2c55b118de67b36d8cd7aa3e217f3a9d23ed2ad9c089d396ae12ed4b3d0fa3cf699c874f21001dcd68d2d8e11ea0d80c3721c7a961ab416dbf6351b81ba036b22b25c739614aa9c724555082c0c61d8600bbf5067132ae87773a8eace86519881e9dd89651a6dde6ab0a36e328e38d243e71ffb5dcbc287c163189c254950c1758d7e765b6d51460d94b6c0b8d185b687d3b4b686f0e5615df352747a1b5c3b1a1072
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber4b51e8986bf2670974fecc6dad020f19
    Version3
    Certificate 3d78d7f9764960b2617df4f01eca862a
    FieldValue
    ToBeSigned (TBS) MD51f056ff7d5f874984dc605402b7cb042
    ToBeSigned (TBS) SHA1bdb348353a2203deb4b767914fa1bd7248dd728b
    ToBeSigned (TBS) SHA256a08e79c386083d875014c409c13d144e0a24386132980df11ff59737c8489eb1
    SubjectC=US, O=Symantec Corporation, OU=Symantec Trust Network, CN=Symantec Class 3 SHA256 Code Signing CA
    ValidFrom2013-12-10 00:00:00
    ValidTo2023-12-09 23:59:59
    Signature13851a1e69a937f7a0bda4af7e1d6153fe9d8c5e0ca6751e781723ddfdec1a035539fb7195c7655aa78e30d2445a61db706fda2105c22e73ba49f1d193fe5dc9cd5e03e0899e3f741ed7f7388ba9d6cfbb352f3358a89256d1c84d3b82e6798416fc28b0b147f31da23eee87d9a67fa456a53fad842e29de7cbca8aaa33d0401eaba93a20e502229174c87e43a115fd6a425899b056b2fb4c9014c277b0bac190522a060153fdac9fb4d4c8ffb726777fd2794c7ba350e8849fe8dfd28af4a12bd0db39705de440c15fa362b03dcc15001f1a1115d14e5e2bd274b54be2b845e0fa6c374050aef97c38922b11f77f3bdcd43d4f14ca93fb58b84af64f2d01421
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber3d78d7f9764960b2617df4f01eca862a
    Version3
    Certificate 611993e400000000001c
    FieldValue
    ToBeSigned (TBS) MD578a717e082dcc1cda3458d917e677d14
    ToBeSigned (TBS) SHA14a872e0e51f9b304469cd1dedb496ee9b8b983a4
    ToBeSigned (TBS) SHA256317fa1d234ebc49040ebc5e8746f8997471496051b185a91bdd9dfbb23fab5f8
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. , For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority , G5
    ValidFrom2011-02-22 19:25:17
    ValidTo2021-02-22 19:35:17
    Signature812a82168c34672be503eb347b8ca2a3508af45586f11e8c8eae7dee0319ce72951848ad6211fd20fd3f4706015ae2e06f8c152c4e3c6a506c0b36a3cf7a0d9c42bc5cf819d560e369e6e22341678c6883762b8f93a32ab57fbe59fba9c9b2268fcaa2f3821b983e919527978661ee5b5d076bcd86a8e26580a8e215e2b2be23056aba0cf347934daca48c077939c061123a050d89a3ec9f578984fbecca7c47661491d8b60f195de6b84aacbc47c8714396e63220a5dc7786fd3ce38b71db7b9b03fcb71d3264eb1652a043a3fa2ead59924e7cc7f233424838513a7c38c71b242228401e1a461f17db18f7f027356cb863d9cdb9645d2ba55eefc629b4f2c7f821cc04ba57fd01b6abc667f9e7d3997ff4f522fa72f5fdff3a1c423aa1f98018a5ee8d1cd4669e4501feaaeefffb178f30f7f1cd29c59decb5d549003d85b8cbbb933a276a49c030ae66c9f723283276f9a48356c848ce5a96aaa0cc0cc47fb48e97af6de35427c39f86c0d6e473089705dbd054625e0348c2d59f7fa7668cd09db04fd4d3985f4b7ac97fb22952d01280c70f54b61e67cdc6a06c110384d34875e72afeb03b6e0a3aa66b769905a3f177686133144706fc537f52bd92145c4a246a678caf8d90aad0f679211b93267cc3ce1ebd883892ae45c6196a4950b305f8ae59378a6a250394b1598150e8ba8380b72335f476b9671d5918ad208d94
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber611993e400000000001c
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll
    • fwpkclnt.sys
    • NDIS.SYS

    Imported Functions

    Expand
    • memcpy
    • RtlValidSid
    • IoFreeMdl
    • RtlUnwind
    • KeBugCheckEx
    • RtlCompareMemory
    • KeTickCount
    • _allmul
    • _aulldiv
    • KeQuerySystemTime
    • ExUuidCreate
    • swprintf_s
    • KeInitializeEvent
    • PsCreateSystemThread
    • ZwSetInformationThread
    • ObReferenceObjectByHandle
    • RtlAppendUnicodeToString
    • IoCreateDevice
    • IoCreateSymbolicLink
    • PsTerminateSystemThread
    • MmGetSystemRoutineAddress
    • PsLookupProcessByProcessId
    • IoAllocateMdl
    • MmBuildMdlForNonPagedPool
    • IoReleaseCancelSpinLock
    • PsGetCurrentProcessId
    • IofCompleteRequest
    • IoDeleteSymbolicLink
    • IoDeleteDevice
    • KeWaitForSingleObject
    • ObfDereferenceObject
    • MmAllocatePagesForMdl
    • MmMapLockedPagesSpecifyCache
    • MmFreePagesFromMdl
    • MmUnmapLockedPages
    • KeSetEvent
    • ObOpenObjectByPointer
    • RtlLengthSid
    • SeExports
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • ZwSetSecurityObject
    • ZwQueryValueKey
    • ExDeleteNPagedLookasideList
    • ExInitializeNPagedLookasideList
    • InterlockedPushEntrySList
    • InterlockedPopEntrySList
    • _aullrem
    • ExFreePoolWithTag
    • memset
    • ExAllocatePoolWithTag
    • RtlInitUnicodeString
    • ZwOpenKey
    • ZwClose
    • KeReleaseInStackQueuedSpinLock
    • KeGetCurrentIrql
    • KeAcquireInStackQueuedSpinLock
    • FwpsStreamInjectAsync0
    • FwpmEngineOpen0
    • FwpmProviderAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmProviderContextDeleteByKey0
    • FwpsAcquireClassifyHandle0
    • FwpsQueryPacketInjectionState0
    • FwpsFlowAssociateContext0
    • FwpmSubLayerAdd0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmFreeMemory0
    • FwpmSubLayerEnum0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmCalloutAdd0
    • FwpmFilterAdd0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmTransactionCommit0
    • FwpmTransactionAbort0
    • FwpsCalloutRegister1
    • FwpsCalloutUnregisterByKey0
    • FwpsPendClassify0
    • FwpsInjectionHandleCreate0
    • FwpsCopyStreamDataToBuffer0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpsAllocateNetBufferAndNetBufferList0
    • FwpsInjectTransportSendAsync0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsInjectNetworkSendAsync0
    • FwpsInjectTransportReceiveAsync0
    • FwpsFreeCloneNetBufferList0
    • FwpsInjectionHandleDestroy0
    • FwpsFlowRemoveContext0
    • FwpsCloneStreamData0
    • FwpsCompleteClassify0
    • FwpsReleaseClassifyHandle0
    • FwpsDiscardClonedStreamData0
    • FwpsFreeNetBufferList0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • FwpmBfeStateUnsubscribeChanges0
    • NdisFreeGenericObject
    • NdisInitializeEvent
    • NdisFreeNetBufferListPool
    • NdisGetDataBuffer
    • NdisAdvanceNetBufferDataStart
    • NdisRetreatNetBufferDataStart
    • NdisAllocateNetBufferListPool
    • NdisAllocateGenericObject
    • NdisWaitEvent

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2020-09-15 00:54:17
    MD5e9e4b27f98eb15dcfc01837e7816ad67
    SHA1a3698922e9850404da1888beebb3f70ae3f8d62e
    SHA2560eace788e09c8d3f793a1fad94d35bcfd233f0777873412cd0c8172865562eec
    Authentihash MD56d4517e6348130fe55f11bfd630d857f
    Authentihash SHA160a632e4b838731aad553650d6bc8af3d3d80b26
    Authentihash SHA2568168304169a2453c0c3e0a285c2a07d3b3b83433e0342f6b33400c371af86221
    RichPEHeaderHash MD54c93d23c41f384b75bda01c7ace495d8
    RichPEHeaderHash SHA128695a10b02de9e1ce2d2b70c463f5d3bbaeaf4c
    RichPEHeaderHash SHA2564049be109d3e76b72f97f3faab4a4456933bce7ec4593342fd7046ca2bae226e
    CompanyWindows (R) Win 7 DDK provider
    DescriptionNetFilter SDK WFP Driver (WPP)
    ProductWindows (R) Win 7 DDK driver
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 0108cbaee60728f5bf06e45a56d6f170
    FieldValue
    ToBeSigned (TBS) MD54e8398340fdf2c302ef881776b4626e7
    ToBeSigned (TBS) SHA1483073cdc5b9b560c2d5aa80b62fa184ae4467ba
    ToBeSigned (TBS) SHA256b9d8daa31a25a3c525aa5cb844ced8da586540f20dc0a004209c598a56b95401
    Subject??=CN, ??=, ??=, ??=Private Organization, serialNumber=91420100MA49KFRB44, C=CN, ST=, L=, O=, CN=
    ValidFrom2020-10-26 00:00:00
    ValidTo2022-10-27 23:59:59
    Signature79197d1bcfcf1e9bad9b6e106ff984000ed506986e884b44056fe05b8ea34d36f5b368551ee2848e3a9f55caad769e641dfb27e2a7182ceaf33b7b7a96a0f0ee966cb67377c2ceebdb72e7672079721ebfe265f3f3e95aa080d0f53fbf70b810e6af342243e6d7af74a9c9e0cec31200ab074e500ef8f8d11541d3409ee0a42835e8a6ce2b19385a2738d00b8e31f874c41e5cea3e30bee081840a3c83ad3aba7aff0240caacc839c0bdab5448d3376f3d7360eb77ba366cb7e3364f638ba48b37e82f03baa20868717f6c58a0175dd5417d1670e97c8dc8b6b021e39f5ce087b63a6de6f46968d7ee37135d40b309b56c12e314b46cd74a51638196a2e02e1c
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber0108cbaee60728f5bf06e45a56d6f170
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 0dd0e3374ac95bdbfa6b434b2a48ec06
    FieldValue
    ToBeSigned (TBS) MD5f92649915476229b093c211c2b18e6c4
    ToBeSigned (TBS) SHA12d54c16a8f8b69ccdea48d0603c132f547a5cf75
    ToBeSigned (TBS) SHA2562cd702a7dec30aa441345672e8992ef9770ce4946f276d767b45b0ed627658fb
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert EV Code Signing CA
    ValidFrom2012-04-18 12:00:00
    ValidTo2027-04-18 12:00:00
    Signature9e5b963a2e1288acab016da49f75e40187a3a532d7bcbaa97ea3d61417f7c2136b7c738f2b6ae50f265968b08e259b6ceffa6c939208c14dcf459e9c46d61e74a19b14a3fa012f4ab101e1724048111368b9369d914bd7c2391210c1c4dcbb6214142a615d4f387c661fc61bffadbe4f7f945b7343000f4d73b751cf0ef677c05bcd348cd96313aa0e6111d6f28e27fcb47bb8b91120918678ea0ed428ff2ad52438e837b2ec96bb9fbc4a1650e15ebf517d23a032c7c1949e7ac9c026a2cc2587a0127e749f2d8db1c8e784beb9d1e9debb6a4e887371e12238cb2487e9737e51b2ff98eb4e7e2fe0ca0efab35ed1ba0542a8489f83f63fc4caa8df68a05061
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber0dd0e3374ac95bdbfa6b434b2a48ec06
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll
    • fwpkclnt.sys
    • NDIS.SYS

    Imported Functions

    Expand
    • memcpy
    • RtlValidSid
    • IoFreeMdl
    • RtlUnwind
    • KeBugCheckEx
    • RtlCompareMemory
    • KeTickCount
    • _allmul
    • _aulldiv
    • KeQuerySystemTime
    • ExUuidCreate
    • swprintf_s
    • KeInitializeEvent
    • PsCreateSystemThread
    • ZwSetInformationThread
    • ObReferenceObjectByHandle
    • RtlAppendUnicodeToString
    • IoCreateDevice
    • IoCreateSymbolicLink
    • PsTerminateSystemThread
    • MmGetSystemRoutineAddress
    • PsLookupProcessByProcessId
    • IoAllocateMdl
    • MmBuildMdlForNonPagedPool
    • IoReleaseCancelSpinLock
    • PsGetCurrentProcessId
    • IofCompleteRequest
    • IoDeleteSymbolicLink
    • IoDeleteDevice
    • KeWaitForSingleObject
    • ObfDereferenceObject
    • MmAllocatePagesForMdl
    • MmMapLockedPagesSpecifyCache
    • MmFreePagesFromMdl
    • MmUnmapLockedPages
    • KeSetEvent
    • ObOpenObjectByPointer
    • RtlLengthSid
    • SeExports
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • ZwSetSecurityObject
    • ZwQueryValueKey
    • ExDeleteNPagedLookasideList
    • ExInitializeNPagedLookasideList
    • InterlockedPushEntrySList
    • InterlockedPopEntrySList
    • _aullrem
    • ExFreePoolWithTag
    • memset
    • ExAllocatePoolWithTag
    • RtlInitUnicodeString
    • ZwOpenKey
    • ZwClose
    • KeReleaseInStackQueuedSpinLock
    • KeGetCurrentIrql
    • KeAcquireInStackQueuedSpinLock
    • FwpsStreamInjectAsync0
    • FwpmEngineOpen0
    • FwpmProviderAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmProviderContextDeleteByKey0
    • FwpsAcquireClassifyHandle0
    • FwpsQueryPacketInjectionState0
    • FwpsFlowAssociateContext0
    • FwpmSubLayerAdd0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmFreeMemory0
    • FwpmSubLayerEnum0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmCalloutAdd0
    • FwpmFilterAdd0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmTransactionCommit0
    • FwpmTransactionAbort0
    • FwpsCalloutRegister1
    • FwpsCalloutUnregisterByKey0
    • FwpsPendClassify0
    • FwpsInjectionHandleCreate0
    • FwpsCopyStreamDataToBuffer0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpsAllocateNetBufferAndNetBufferList0
    • FwpsInjectTransportSendAsync0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsInjectNetworkSendAsync0
    • FwpsInjectTransportReceiveAsync0
    • FwpsFreeCloneNetBufferList0
    • FwpsInjectionHandleDestroy0
    • FwpsFlowRemoveContext0
    • FwpsCloneStreamData0
    • FwpsCompleteClassify0
    • FwpsReleaseClassifyHandle0
    • FwpsDiscardClonedStreamData0
    • FwpsFreeNetBufferList0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • FwpmBfeStateUnsubscribeChanges0
    • NdisFreeGenericObject
    • NdisInitializeEvent
    • NdisFreeNetBufferListPool
    • NdisGetDataBuffer
    • NdisAdvanceNetBufferDataStart
    • NdisRetreatNetBufferDataStart
    • NdisAllocateNetBufferListPool
    • NdisAllocateGenericObject
    • NdisWaitEvent

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2019-06-10 08:45:55
    MD56088826a0114f777e486ff093a8d4150
    SHA1abce61b428d48fabdb8ddfff4d61d2f1edac0128
    SHA25618b923b169b2c3c7db5cbfda0db0999f04adb2cf6c917e5b1fb2ff04714ecac1
    Authentihash MD5ddbb824860937add7c0f86c5df993d3a
    Authentihash SHA103f0dd3124ec3a4bb6d30865a488f54e74ded699
    Authentihash SHA256dfaefd06b680f9ea837e7815fc1cc7d1f4cc375641ac850667ab20739f46ad22
    RichPEHeaderHash MD5a8cfc1c4c595dbd9909445a5e7ed9a54
    RichPEHeaderHash SHA193a8f9bf4e4c8886fc1d435828ab6706d11cfdf9
    RichPEHeaderHash SHA256dd65f865e9c50e9dde3584d90f0927d21042665aa375918708b4792861041072
    Company宏图无忧
    DescriptionWYJSQ TDI Hook Driver (WPP)
    Product无忧加速器驱动文件
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 09450b8f73ea43e39d2cdd56049dbe40
    FieldValue
    ToBeSigned (TBS) MD5bcfecc67375f580ac6eadd789860b1f8
    ToBeSigned (TBS) SHA13fa9cf13a1816a6e358bb1ca12e050662bc2e178
    ToBeSigned (TBS) SHA256fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df
    SubjectC=CN, ST=, L=, O=, CN=
    ValidFrom2019-06-27 00:00:00
    ValidTo2020-06-30 12:00:00
    Signature03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber09450b8f73ea43e39d2cdd56049dbe40
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 02c4d1e58a4a680c568da3047e7e4d5f
    FieldValue
    ToBeSigned (TBS) MD5829995f702421dea833a24fb2c7f4442
    ToBeSigned (TBS) SHA11d7e838accd498c2e5ba9373af819ec097bb955c
    ToBeSigned (TBS) SHA25692914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1
    ValidFrom2011-02-11 12:00:00
    ValidTo2026-02-10 12:00:00
    Signature49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber02c4d1e58a4a680c568da3047e7e4d5f
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • TDI.SYS

    Imported Functions

    Expand
    • KeReleaseSpinLock
    • KeAcquireSpinLockRaiseToDpc
    • IoDeleteSymbolicLink
    • PsLookupProcessByProcessId
    • RtlInitUnicodeString
    • IoDeleteDevice
    • MmGetSystemRoutineAddress
    • ZwClose
    • IofCompleteRequest
    • IoCreateSymbolicLink
    • ObfDereferenceObject
    • IoCreateDevice
    • ObOpenObjectByPointer
    • IofCallDriver
    • IoDetachDevice
    • IoBuildDeviceIoControlRequest
    • RtlDowncaseUnicodeString
    • KeInitializeEvent
    • MmBuildMdlForNonPagedPool
    • IoFreeMdl
    • KeInsertQueueDpc
    • KeWaitForSingleObject
    • PsGetCurrentProcessId
    • IoAllocateMdl
    • ExFreePoolWithTag
    • IoFreeIrp
    • IoReleaseCancelSpinLock
    • MmMapLockedPagesSpecifyCache
    • IoAllocateIrp
    • KeInitializeTimer
    • RtlAppendUnicodeToString
    • KeInitializeDpc
    • IoGetDeviceObjectPointer
    • IoAttachDeviceToDeviceStack
    • KeSetTimer
    • ObfReferenceObject
    • MmFreePagesFromMdl
    • MmUnmapLockedPages
    • MmAllocatePagesForMdl
    • RtlCreateAcl
    • RtlSetDaclSecurityDescriptor
    • RtlAddAccessAllowedAce
    • ZwQueryValueKey
    • ZwSetSecurityObject
    • SeExports
    • RtlLengthSid
    • RtlCreateSecurityDescriptor
    • ZwOpenKey
    • KeBugCheckEx
    • ObReferenceObjectByHandle
    • ExAllocatePoolWithTag
    • __C_specific_handler
    • TdiMapUserRequest

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2019-06-10 08:45:55
    MD5c56a3a74019e2304af8c19e8e17dd9d3
    SHA191f693850d7e42ae135e07eae6940e0f58dc4de7
    SHA256edc6e32e3545f859e5b49ece1cabd13623122c1f03a2f7454a61034b3ff577ed
    Authentihash MD5ddbb824860937add7c0f86c5df993d3a
    Authentihash SHA103f0dd3124ec3a4bb6d30865a488f54e74ded699
    Authentihash SHA256dfaefd06b680f9ea837e7815fc1cc7d1f4cc375641ac850667ab20739f46ad22
    RichPEHeaderHash MD5a8cfc1c4c595dbd9909445a5e7ed9a54
    RichPEHeaderHash SHA193a8f9bf4e4c8886fc1d435828ab6706d11cfdf9
    RichPEHeaderHash SHA256dd65f865e9c50e9dde3584d90f0927d21042665aa375918708b4792861041072
    Company宏图无忧
    DescriptionWYJSQ TDI Hook Driver (WPP)
    Product无忧加速器驱动文件
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 09450b8f73ea43e39d2cdd56049dbe40
    FieldValue
    ToBeSigned (TBS) MD5bcfecc67375f580ac6eadd789860b1f8
    ToBeSigned (TBS) SHA13fa9cf13a1816a6e358bb1ca12e050662bc2e178
    ToBeSigned (TBS) SHA256fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df
    SubjectC=CN, ST=, L=, O=, CN=
    ValidFrom2019-06-27 00:00:00
    ValidTo2020-06-30 12:00:00
    Signature03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber09450b8f73ea43e39d2cdd56049dbe40
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 02c4d1e58a4a680c568da3047e7e4d5f
    FieldValue
    ToBeSigned (TBS) MD5829995f702421dea833a24fb2c7f4442
    ToBeSigned (TBS) SHA11d7e838accd498c2e5ba9373af819ec097bb955c
    ToBeSigned (TBS) SHA25692914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1
    ValidFrom2011-02-11 12:00:00
    ValidTo2026-02-10 12:00:00
    Signature49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber02c4d1e58a4a680c568da3047e7e4d5f
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • TDI.SYS

    Imported Functions

    Expand
    • KeReleaseSpinLock
    • KeAcquireSpinLockRaiseToDpc
    • IoDeleteSymbolicLink
    • PsLookupProcessByProcessId
    • RtlInitUnicodeString
    • IoDeleteDevice
    • MmGetSystemRoutineAddress
    • ZwClose
    • IofCompleteRequest
    • IoCreateSymbolicLink
    • ObfDereferenceObject
    • IoCreateDevice
    • ObOpenObjectByPointer
    • IofCallDriver
    • IoDetachDevice
    • IoBuildDeviceIoControlRequest
    • RtlDowncaseUnicodeString
    • KeInitializeEvent
    • MmBuildMdlForNonPagedPool
    • IoFreeMdl
    • KeInsertQueueDpc
    • KeWaitForSingleObject
    • PsGetCurrentProcessId
    • IoAllocateMdl
    • ExFreePoolWithTag
    • IoFreeIrp
    • IoReleaseCancelSpinLock
    • MmMapLockedPagesSpecifyCache
    • IoAllocateIrp
    • KeInitializeTimer
    • RtlAppendUnicodeToString
    • KeInitializeDpc
    • IoGetDeviceObjectPointer
    • IoAttachDeviceToDeviceStack
    • KeSetTimer
    • ObfReferenceObject
    • MmFreePagesFromMdl
    • MmUnmapLockedPages
    • MmAllocatePagesForMdl
    • RtlCreateAcl
    • RtlSetDaclSecurityDescriptor
    • RtlAddAccessAllowedAce
    • ZwQueryValueKey
    • ZwSetSecurityObject
    • SeExports
    • RtlLengthSid
    • RtlCreateSecurityDescriptor
    • ZwOpenKey
    • KeBugCheckEx
    • ObReferenceObjectByHandle
    • ExAllocatePoolWithTag
    • __C_specific_handler
    • TdiMapUserRequest

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2019-06-10 08:45:52
    MD5e3b79b124fe408b971d18fd3a25b5ba0
    SHA15d1338b06e52a2dd3afda4dd0374a80e91cbf333
    SHA2562fa78c2988f9580b0c18822b117d065fb419f9c476f4cfa43925ba6cd2dffac3
    Authentihash MD5b42afd5a5225094c7943185e769bc995
    Authentihash SHA122c5e127e7e7c567d8624607a6f8f5809deacb55
    Authentihash SHA256de6bf572d39e2611773e7a01f0388f84fb25da6cba2f1f8b9b36ffba467de6fa
    RichPEHeaderHash MD5ea1a25e78d69ef318ef4d2fbfd420541
    RichPEHeaderHash SHA11f795bc5eaecf5ee96f77ae703426b5f65e0d895
    RichPEHeaderHash SHA2561c10422043879162a1e9a246a3125f545a119afc8c25fd6822f48509ee2a02c0
    Company宏图无忧
    DescriptionWYJSQ TDI Hook Driver (WPP)
    Product无忧加速器
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 09450b8f73ea43e39d2cdd56049dbe40
    FieldValue
    ToBeSigned (TBS) MD5bcfecc67375f580ac6eadd789860b1f8
    ToBeSigned (TBS) SHA13fa9cf13a1816a6e358bb1ca12e050662bc2e178
    ToBeSigned (TBS) SHA256fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df
    SubjectC=CN, ST=, L=, O=, CN=
    ValidFrom2019-06-27 00:00:00
    ValidTo2020-06-30 12:00:00
    Signature03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber09450b8f73ea43e39d2cdd56049dbe40
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 02c4d1e58a4a680c568da3047e7e4d5f
    FieldValue
    ToBeSigned (TBS) MD5829995f702421dea833a24fb2c7f4442
    ToBeSigned (TBS) SHA11d7e838accd498c2e5ba9373af819ec097bb955c
    ToBeSigned (TBS) SHA25692914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1
    ValidFrom2011-02-11 12:00:00
    ValidTo2026-02-10 12:00:00
    Signature49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber02c4d1e58a4a680c568da3047e7e4d5f
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll
    • TDI.SYS

    Imported Functions

    Expand
    • IoCreateSymbolicLink
    • IoCreateDevice
    • IoDeleteSymbolicLink
    • IofCompleteRequest
    • ZwClose
    • ObfDereferenceObject
    • ObOpenObjectByPointer
    • PsLookupProcessByProcessId
    • MmGetSystemRoutineAddress
    • RtlInitUnicodeString
    • IoDetachDevice
    • IofCallDriver
    • IoFreeMdl
    • memcpy
    • MmBuildMdlForNonPagedPool
    • IoBuildDeviceIoControlRequest
    • IoAllocateMdl
    • RtlDowncaseUnicodeString
    • PsGetCurrentProcessId
    • KeWaitForSingleObject
    • KeInitializeEvent
    • KeInsertQueueDpc
    • IoReleaseCancelSpinLock
    • ObReferenceObjectByHandle
    • IoDeleteDevice
    • MmMapLockedPagesSpecifyCache
    • IoAllocateIrp
    • KeInitializeTimer
    • KeInitializeDpc
    • RtlAppendUnicodeToString
    • IoAttachDeviceToDeviceStack
    • IoGetDeviceObjectPointer
    • ObfReferenceObject
    • KeSetTimer
    • MmFreePagesFromMdl
    • MmUnmapLockedPages
    • MmAllocatePagesForMdl
    • ZwQueryValueKey
    • ZwOpenKey
    • ZwSetSecurityObject
    • RtlSetDaclSecurityDescriptor
    • RtlCreateSecurityDescriptor
    • RtlAddAccessAllowedAce
    • RtlCreateAcl
    • RtlLengthSid
    • SeExports
    • KeTickCount
    • KeBugCheckEx
    • _aullrem
    • ExFreePoolWithTag
    • memset
    • IoFreeIrp
    • ExAllocatePoolWithTag
    • RtlUnwind
    • KfAcquireSpinLock
    • KfReleaseSpinLock
    • TdiMapUserRequest

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2020-09-15 00:54:42
    MD5e1190b7a0bd3b8cc3a819d471ede264f
    SHA11ea5d1bad9b01a38aa20b2cc2fcd90b3adcb1700
    SHA25665a3e69854c729659281d2c5f8a4c8274ad3606befdcd9e1b79d3262f260bfa1
    Authentihash MD552cef25aecab8b66f05e29df206d6375
    Authentihash SHA14e5e719362cd48bb323803c1d00afde11d4b9d4c
    Authentihash SHA25644a0599defea351314663582dbc61069b3a095a4ddad571bb17dd0d8b21e7ff2
    RichPEHeaderHash MD5b873ce00fb531a917db2341eff66f88d
    RichPEHeaderHash SHA10f24abad7feabd2abb4b819dedc5ab9b9de3e33c
    RichPEHeaderHash SHA25654b267b1987fc423443455d94ce6d7b42dd9357bef9de2d67bea3bc6a83fb0cc
    CompanyWindows (R) Win 7 DDK provider
    DescriptionNetFilter SDK WFP Driver (WPP)
    ProductWindows (R) Win 7 DDK driver
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 0af5efac8e1cb5bb290394d315079dbe
    FieldValue
    ToBeSigned (TBS) MD511e15766710ca8d294dcaf75cdc481c7
    ToBeSigned (TBS) SHA1d4fbc4f59e8ac285a2a1cdde885eab8ec7c073f2
    ToBeSigned (TBS) SHA2568235db8c900fcefb648b477bd93a19628b36ff95f3c53237eeae5d3dc6edb450
    Subject??=CN, ??=, ??=, ??=Private Organization, serialNumber=91330701MA28DMHT4Y, C=CN, ST=, L=, O=, CN=
    ValidFrom2019-03-22 00:00:00
    ValidTo2021-03-25 12:00:00
    Signature5e1cb6b58ffb591e3a704dc59756f1ecc243200154b08df383197a63b507099accf1fb5302f3868ccebd3057fbab16d7a9bdcf143a9502d3489e7f673d0fd81c4feb5f98561f7c0971d93ed826da97dbd0622d55a14be6cffd7c18b7668fb800afba5c12037b1d673409daf19e06dc378ff0da81facc1c3d85f5f740a83a01c1ab827c9fe78ef252f1e8f0d91eb9d231f88f155d5571ca01bc222a1e6efedd466d2fab104e7eb1d390df00fc22e006ff9d5291b720faa6b907f8e5440b2f6b3284fc4e91c9c16a2ab3ccc977f147709117e1d97824663e55602037259f03488ce6f6ab82476b2ff21df0351d53690bb404bff4c78f419ab59b10e97751c5442d
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber0af5efac8e1cb5bb290394d315079dbe
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 0dd0e3374ac95bdbfa6b434b2a48ec06
    FieldValue
    ToBeSigned (TBS) MD5f92649915476229b093c211c2b18e6c4
    ToBeSigned (TBS) SHA12d54c16a8f8b69ccdea48d0603c132f547a5cf75
    ToBeSigned (TBS) SHA2562cd702a7dec30aa441345672e8992ef9770ce4946f276d767b45b0ed627658fb
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert EV Code Signing CA
    ValidFrom2012-04-18 12:00:00
    ValidTo2027-04-18 12:00:00
    Signature9e5b963a2e1288acab016da49f75e40187a3a532d7bcbaa97ea3d61417f7c2136b7c738f2b6ae50f265968b08e259b6ceffa6c939208c14dcf459e9c46d61e74a19b14a3fa012f4ab101e1724048111368b9369d914bd7c2391210c1c4dcbb6214142a615d4f387c661fc61bffadbe4f7f945b7343000f4d73b751cf0ef677c05bcd348cd96313aa0e6111d6f28e27fcb47bb8b91120918678ea0ed428ff2ad52438e837b2ec96bb9fbc4a1650e15ebf517d23a032c7c1949e7ac9c026a2cc2587a0127e749f2d8db1c8e784beb9d1e9debb6a4e887371e12238cb2487e9737e51b2ff98eb4e7e2fe0ca0efab35ed1ba0542a8489f83f63fc4caa8df68a05061
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber0dd0e3374ac95bdbfa6b434b2a48ec06
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • NDIS.SYS
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • FwpmTransactionCommit0
    • FwpmTransactionAbort0
    • FwpmProviderAdd0
    • FwpmProviderContextDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmSubLayerEnum0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmCalloutAdd0
    • FwpmFilterAdd0
    • FwpsFlowAbort0
    • FwpsInjectionHandleCreate0
    • FwpsInjectionHandleDestroy0
    • FwpsAllocateNetBufferAndNetBufferList0
    • FwpsFreeNetBufferList0
    • FwpmTransactionBegin0
    • FwpsInjectNetworkSendAsync0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsInjectTransportSendAsync0
    • FwpsInjectTransportReceiveAsync0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsStreamInjectAsync0
    • FwpsCopyStreamDataToBuffer0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • FwpmBfeStateUnsubscribeChanges0
    • FwpsFlowRemoveContext0
    • FwpsCompleteClassify0
    • FwpsRedirectHandleDestroy0
    • FwpsCloneStreamData0
    • FwpsDiscardClonedStreamData0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpmFreeMemory0
    • FwpsRedirectHandleCreate0
    • FwpsQueryPacketInjectionState0
    • FwpsApplyModifiedLayerData0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsReleaseClassifyHandle0
    • FwpsFlowAssociateContext0
    • FwpsAcquireClassifyHandle0
    • FwpsCalloutUnregisterByKey0
    • FwpsCalloutRegister1
    • FwpsPendClassify0
    • FwpsFreeCloneNetBufferList0
    • NdisAllocateNetBufferListPool
    • NdisWaitEvent
    • NdisInitializeEvent
    • NdisFreeGenericObject
    • NdisAllocateGenericObject
    • NdisGetDataBuffer
    • NdisAdvanceNetBufferDataStart
    • NdisRetreatNetBufferDataStart
    • NdisFreeNetBufferListPool
    • memset
    • RtlInitUnicodeString
    • MmGetSystemRoutineAddress
    • RtlAppendUnicodeToString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeInitializeEvent
    • KeSetEvent
    • KeWaitForSingleObject
    • KeInitializeSpinLock
    • ExFreePoolWithTag
    • InterlockedPopEntrySList
    • InterlockedPushEntrySList
    • ExInitializeNPagedLookasideList
    • ExDeleteNPagedLookasideList
    • MmBuildMdlForNonPagedPool
    • MmMapLockedPagesSpecifyCache
    • MmUnmapLockedPages
    • MmAllocatePagesForMdl
    • MmFreePagesFromMdl
    • PsCreateSystemThread
    • PsTerminateSystemThread
    • IoAllocateMdl
    • IofCompleteRequest
    • IoCreateDevice
    • IoCreateSymbolicLink
    • IoDeleteDevice
    • IoDeleteSymbolicLink
    • IoFreeMdl
    • IoReleaseCancelSpinLock
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwClose
    • ZwOpenKey
    • ZwQueryValueKey
    • PsGetCurrentProcessId
    • ZwSetInformationThread
    • RtlLengthSid
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwSetSecurityObject
    • SeExports
    • RtlGetVersion
    • KeQuerySystemTime
    • _allmul
    • _aulldiv
    • _aullrem
    • RtlCompareMemory
    • RtlValidSid
    • RtlUnwind
    • memcpy
    • ExUuidCreate
    • ExAllocatePoolWithTag
    • swprintf_s
    • KeReleaseInStackQueuedSpinLock
    • KeGetCurrentIrql
    • KeAcquireInStackQueuedSpinLock

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2020-09-15 00:54:17
    MD53a53fe6598d2b9bc3b81d3dd6bc5d843
    SHA18fbe153c1059a7fce265d5f6e6d8836c3aebe39e
    SHA256f488500be4eaafba74b644be95d4c0523297770fb9bb78c449f643ab8d4a05d9
    Authentihash MD56d4517e6348130fe55f11bfd630d857f
    Authentihash SHA160a632e4b838731aad553650d6bc8af3d3d80b26
    Authentihash SHA2568168304169a2453c0c3e0a285c2a07d3b3b83433e0342f6b33400c371af86221
    RichPEHeaderHash MD54c93d23c41f384b75bda01c7ace495d8
    RichPEHeaderHash SHA128695a10b02de9e1ce2d2b70c463f5d3bbaeaf4c
    RichPEHeaderHash SHA2564049be109d3e76b72f97f3faab4a4456933bce7ec4593342fd7046ca2bae226e
    CompanyWindows (R) Win 7 DDK provider
    DescriptionNetFilter SDK WFP Driver (WPP)
    ProductWindows (R) Win 7 DDK driver
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 0af5efac8e1cb5bb290394d315079dbe
    FieldValue
    ToBeSigned (TBS) MD511e15766710ca8d294dcaf75cdc481c7
    ToBeSigned (TBS) SHA1d4fbc4f59e8ac285a2a1cdde885eab8ec7c073f2
    ToBeSigned (TBS) SHA2568235db8c900fcefb648b477bd93a19628b36ff95f3c53237eeae5d3dc6edb450
    Subject??=CN, ??=, ??=, ??=Private Organization, serialNumber=91330701MA28DMHT4Y, C=CN, ST=, L=, O=, CN=
    ValidFrom2019-03-22 00:00:00
    ValidTo2021-03-25 12:00:00
    Signature5e1cb6b58ffb591e3a704dc59756f1ecc243200154b08df383197a63b507099accf1fb5302f3868ccebd3057fbab16d7a9bdcf143a9502d3489e7f673d0fd81c4feb5f98561f7c0971d93ed826da97dbd0622d55a14be6cffd7c18b7668fb800afba5c12037b1d673409daf19e06dc378ff0da81facc1c3d85f5f740a83a01c1ab827c9fe78ef252f1e8f0d91eb9d231f88f155d5571ca01bc222a1e6efedd466d2fab104e7eb1d390df00fc22e006ff9d5291b720faa6b907f8e5440b2f6b3284fc4e91c9c16a2ab3ccc977f147709117e1d97824663e55602037259f03488ce6f6ab82476b2ff21df0351d53690bb404bff4c78f419ab59b10e97751c5442d
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber0af5efac8e1cb5bb290394d315079dbe
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 0dd0e3374ac95bdbfa6b434b2a48ec06
    FieldValue
    ToBeSigned (TBS) MD5f92649915476229b093c211c2b18e6c4
    ToBeSigned (TBS) SHA12d54c16a8f8b69ccdea48d0603c132f547a5cf75
    ToBeSigned (TBS) SHA2562cd702a7dec30aa441345672e8992ef9770ce4946f276d767b45b0ed627658fb
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert EV Code Signing CA
    ValidFrom2012-04-18 12:00:00
    ValidTo2027-04-18 12:00:00
    Signature9e5b963a2e1288acab016da49f75e40187a3a532d7bcbaa97ea3d61417f7c2136b7c738f2b6ae50f265968b08e259b6ceffa6c939208c14dcf459e9c46d61e74a19b14a3fa012f4ab101e1724048111368b9369d914bd7c2391210c1c4dcbb6214142a615d4f387c661fc61bffadbe4f7f945b7343000f4d73b751cf0ef677c05bcd348cd96313aa0e6111d6f28e27fcb47bb8b91120918678ea0ed428ff2ad52438e837b2ec96bb9fbc4a1650e15ebf517d23a032c7c1949e7ac9c026a2cc2587a0127e749f2d8db1c8e784beb9d1e9debb6a4e887371e12238cb2487e9737e51b2ff98eb4e7e2fe0ca0efab35ed1ba0542a8489f83f63fc4caa8df68a05061
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber0dd0e3374ac95bdbfa6b434b2a48ec06
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll
    • fwpkclnt.sys
    • NDIS.SYS

    Imported Functions

    Expand
    • memcpy
    • RtlValidSid
    • IoFreeMdl
    • RtlUnwind
    • KeBugCheckEx
    • RtlCompareMemory
    • KeTickCount
    • _allmul
    • _aulldiv
    • KeQuerySystemTime
    • ExUuidCreate
    • swprintf_s
    • KeInitializeEvent
    • PsCreateSystemThread
    • ZwSetInformationThread
    • ObReferenceObjectByHandle
    • RtlAppendUnicodeToString
    • IoCreateDevice
    • IoCreateSymbolicLink
    • PsTerminateSystemThread
    • MmGetSystemRoutineAddress
    • PsLookupProcessByProcessId
    • IoAllocateMdl
    • MmBuildMdlForNonPagedPool
    • IoReleaseCancelSpinLock
    • PsGetCurrentProcessId
    • IofCompleteRequest
    • IoDeleteSymbolicLink
    • IoDeleteDevice
    • KeWaitForSingleObject
    • ObfDereferenceObject
    • MmAllocatePagesForMdl
    • MmMapLockedPagesSpecifyCache
    • MmFreePagesFromMdl
    • MmUnmapLockedPages
    • KeSetEvent
    • ObOpenObjectByPointer
    • RtlLengthSid
    • SeExports
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • ZwSetSecurityObject
    • ZwQueryValueKey
    • ExDeleteNPagedLookasideList
    • ExInitializeNPagedLookasideList
    • InterlockedPushEntrySList
    • InterlockedPopEntrySList
    • _aullrem
    • ExFreePoolWithTag
    • memset
    • ExAllocatePoolWithTag
    • RtlInitUnicodeString
    • ZwOpenKey
    • ZwClose
    • KeReleaseInStackQueuedSpinLock
    • KeGetCurrentIrql
    • KeAcquireInStackQueuedSpinLock
    • FwpsStreamInjectAsync0
    • FwpmEngineOpen0
    • FwpmProviderAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmProviderContextDeleteByKey0
    • FwpsAcquireClassifyHandle0
    • FwpsQueryPacketInjectionState0
    • FwpsFlowAssociateContext0
    • FwpmSubLayerAdd0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmFreeMemory0
    • FwpmSubLayerEnum0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmCalloutAdd0
    • FwpmFilterAdd0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmTransactionCommit0
    • FwpmTransactionAbort0
    • FwpsCalloutRegister1
    • FwpsCalloutUnregisterByKey0
    • FwpsPendClassify0
    • FwpsInjectionHandleCreate0
    • FwpsCopyStreamDataToBuffer0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpsAllocateNetBufferAndNetBufferList0
    • FwpsInjectTransportSendAsync0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsInjectNetworkSendAsync0
    • FwpsInjectTransportReceiveAsync0
    • FwpsFreeCloneNetBufferList0
    • FwpsInjectionHandleDestroy0
    • FwpsFlowRemoveContext0
    • FwpsCloneStreamData0
    • FwpsCompleteClassify0
    • FwpsReleaseClassifyHandle0
    • FwpsDiscardClonedStreamData0
    • FwpsFreeNetBufferList0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • FwpmBfeStateUnsubscribeChanges0
    • NdisFreeGenericObject
    • NdisInitializeEvent
    • NdisFreeNetBufferListPool
    • NdisGetDataBuffer
    • NdisAdvanceNetBufferDataStart
    • NdisRetreatNetBufferDataStart
    • NdisAllocateNetBufferListPool
    • NdisAllocateGenericObject
    • NdisWaitEvent

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2020-09-15 00:54:41
    MD5837b27efec864ae45d89cfffc1e635f0
    SHA1f03a9bb8c6943c3db7532ccc39cc1905a62f27be
    SHA2560f3e7bf7b103613844a38afb574817ddaecd00e4d206d891660dbb0e5dfee04e
    Authentihash MD53361957860d2b65c0368778ca088946f
    Authentihash SHA16a784d45517142c11d5cca3ff9956b2ed6eaf4c9
    Authentihash SHA256e94e8a87459db56837d1c58f9854794aa99f36566a9ded9b398be9d4d3a2c2af
    RichPEHeaderHash MD5c646eed94ec9e75c1a5498d3642cdab3
    RichPEHeaderHash SHA10d0761641e424cc895ba76723784427fcf297f4a
    RichPEHeaderHash SHA2567cecb42d3d4ae8649f3b4714fbab29c4cef8e24a48b0eea2537824fc40f4ea7f
    CompanyWindows (R) Win 7 DDK provider
    DescriptionNetFilter SDK WFP Driver (WPP)
    ProductWindows (R) Win 7 DDK driver
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 0af5efac8e1cb5bb290394d315079dbe
    FieldValue
    ToBeSigned (TBS) MD511e15766710ca8d294dcaf75cdc481c7
    ToBeSigned (TBS) SHA1d4fbc4f59e8ac285a2a1cdde885eab8ec7c073f2
    ToBeSigned (TBS) SHA2568235db8c900fcefb648b477bd93a19628b36ff95f3c53237eeae5d3dc6edb450
    Subject??=CN, ??=, ??=, ??=Private Organization, serialNumber=91330701MA28DMHT4Y, C=CN, ST=, L=, O=, CN=
    ValidFrom2019-03-22 00:00:00
    ValidTo2021-03-25 12:00:00
    Signature5e1cb6b58ffb591e3a704dc59756f1ecc243200154b08df383197a63b507099accf1fb5302f3868ccebd3057fbab16d7a9bdcf143a9502d3489e7f673d0fd81c4feb5f98561f7c0971d93ed826da97dbd0622d55a14be6cffd7c18b7668fb800afba5c12037b1d673409daf19e06dc378ff0da81facc1c3d85f5f740a83a01c1ab827c9fe78ef252f1e8f0d91eb9d231f88f155d5571ca01bc222a1e6efedd466d2fab104e7eb1d390df00fc22e006ff9d5291b720faa6b907f8e5440b2f6b3284fc4e91c9c16a2ab3ccc977f147709117e1d97824663e55602037259f03488ce6f6ab82476b2ff21df0351d53690bb404bff4c78f419ab59b10e97751c5442d
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber0af5efac8e1cb5bb290394d315079dbe
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 0dd0e3374ac95bdbfa6b434b2a48ec06
    FieldValue
    ToBeSigned (TBS) MD5f92649915476229b093c211c2b18e6c4
    ToBeSigned (TBS) SHA12d54c16a8f8b69ccdea48d0603c132f547a5cf75
    ToBeSigned (TBS) SHA2562cd702a7dec30aa441345672e8992ef9770ce4946f276d767b45b0ed627658fb
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert EV Code Signing CA
    ValidFrom2012-04-18 12:00:00
    ValidTo2027-04-18 12:00:00
    Signature9e5b963a2e1288acab016da49f75e40187a3a532d7bcbaa97ea3d61417f7c2136b7c738f2b6ae50f265968b08e259b6ceffa6c939208c14dcf459e9c46d61e74a19b14a3fa012f4ab101e1724048111368b9369d914bd7c2391210c1c4dcbb6214142a615d4f387c661fc61bffadbe4f7f945b7343000f4d73b751cf0ef677c05bcd348cd96313aa0e6111d6f28e27fcb47bb8b91120918678ea0ed428ff2ad52438e837b2ec96bb9fbc4a1650e15ebf517d23a032c7c1949e7ac9c026a2cc2587a0127e749f2d8db1c8e784beb9d1e9debb6a4e887371e12238cb2487e9737e51b2ff98eb4e7e2fe0ca0efab35ed1ba0542a8489f83f63fc4caa8df68a05061
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber0dd0e3374ac95bdbfa6b434b2a48ec06
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • NDIS.SYS
    • ntoskrnl.exe

    Imported Functions

    Expand
    • FwpmFreeMemory0
    • FwpmEngineOpen0
    • FwpmEngineClose0
    • FwpmTransactionBegin0
    • FwpmTransactionCommit0
    • FwpmTransactionAbort0
    • FwpmProviderAdd0
    • FwpmProviderContextDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmSubLayerEnum0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmCalloutAdd0
    • FwpmFilterAdd0
    • FwpsFlowAbort0
    • FwpsInjectionHandleCreate0
    • FwpsInjectionHandleDestroy0
    • FwpsRedirectHandleCreate0
    • FwpsFreeNetBufferList0
    • FwpsFreeCloneNetBufferList0
    • FwpsInjectNetworkSendAsync0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsInjectTransportSendAsync0
    • FwpsInjectTransportReceiveAsync0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsStreamInjectAsync0
    • FwpsCopyStreamDataToBuffer0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • FwpmBfeStateUnsubscribeChanges0
    • FwpsFlowRemoveContext0
    • FwpsCompleteClassify0
    • FwpsRedirectHandleDestroy0
    • FwpsCloneStreamData0
    • FwpsDiscardClonedStreamData0
    • FwpsQueryPacketInjectionState0
    • FwpsApplyModifiedLayerData0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsReleaseClassifyHandle0
    • FwpsAcquireClassifyHandle0
    • FwpsFlowAssociateContext0
    • FwpsCalloutUnregisterByKey0
    • FwpsCalloutRegister1
    • FwpsPendClassify0
    • FwpsAllocateNetBufferAndNetBufferList0
    • NdisFreeNetBufferListPool
    • NdisAllocateNetBufferListPool
    • NdisWaitEvent
    • NdisInitializeEvent
    • NdisFreeGenericObject
    • NdisAllocateGenericObject
    • NdisGetDataBuffer
    • NdisAdvanceNetBufferDataStart
    • NdisRetreatNetBufferDataStart
    • KeAcquireInStackQueuedSpinLock
    • KeReleaseInStackQueuedSpinLock
    • ExAllocatePoolWithTag
    • ExUuidCreate
    • swprintf_s
    • RtlInitUnicodeString
    • MmGetSystemRoutineAddress
    • RtlAppendUnicodeToString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeInitializeEvent
    • KeSetEvent
    • KeWaitForSingleObject
    • KeInitializeSpinLock
    • ExFreePoolWithTag
    • ExQueryDepthSList
    • ExpInterlockedPopEntrySList
    • ExpInterlockedPushEntrySList
    • ExInitializeNPagedLookasideList
    • ExDeleteNPagedLookasideList
    • MmBuildMdlForNonPagedPool
    • MmMapLockedPagesSpecifyCache
    • MmUnmapLockedPages
    • MmAllocatePagesForMdl
    • MmFreePagesFromMdl
    • PsCreateSystemThread
    • PsTerminateSystemThread
    • IoAllocateMdl
    • IofCompleteRequest
    • IoCreateDevice
    • IoCreateSymbolicLink
    • IoDeleteDevice
    • IoDeleteSymbolicLink
    • IoFreeMdl
    • IoReleaseCancelSpinLock
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwClose
    • ZwOpenKey
    • ZwQueryValueKey
    • PsGetCurrentProcessId
    • ZwSetInformationThread
    • RtlLengthSid
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwSetSecurityObject
    • __C_specific_handler
    • SeExports
    • RtlGetVersion
    • RtlCompareMemory
    • RtlValidSid

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2019-06-10 08:45:42
    MD55035359be554444dde135903e4a07b28
    SHA15686bec46dedcea3a8724bb042a1d24ddd6f4c81
    SHA25612656fc113b178fa3e6bfffc6473897766c44120082483eb8059ebff29b5d2df
    Authentihash MD5fd8b9266dc98e0af514babcbba122265
    Authentihash SHA1dc38cc55b84a1a7c0846fb5509b43b4ff97a9be6
    Authentihash SHA256fafa1bb36f0ac34b762a10e9f327dcab2152a6d0b16a19697362d49a31e7f566
    RichPEHeaderHash MD5a56ba6fc66a7556100c90b00913a984c
    RichPEHeaderHash SHA1b236fd12e7887836407fd8ff0acd7192685f3704
    RichPEHeaderHash SHA256464507424adf04e3a3c84ab69df0eb8a21f311a35cdf11ad898a50995fbfba19
    Company宏图无忧
    DescriptionWYJSQ WFP Driver (WPP)
    Product无忧加速器
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 09450b8f73ea43e39d2cdd56049dbe40
    FieldValue
    ToBeSigned (TBS) MD5bcfecc67375f580ac6eadd789860b1f8
    ToBeSigned (TBS) SHA13fa9cf13a1816a6e358bb1ca12e050662bc2e178
    ToBeSigned (TBS) SHA256fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df
    SubjectC=CN, ST=, L=, O=, CN=
    ValidFrom2019-06-27 00:00:00
    ValidTo2020-06-30 12:00:00
    Signature03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber09450b8f73ea43e39d2cdd56049dbe40
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 02c4d1e58a4a680c568da3047e7e4d5f
    FieldValue
    ToBeSigned (TBS) MD5829995f702421dea833a24fb2c7f4442
    ToBeSigned (TBS) SHA11d7e838accd498c2e5ba9373af819ec097bb955c
    ToBeSigned (TBS) SHA25692914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1
    ValidFrom2011-02-11 12:00:00
    ValidTo2026-02-10 12:00:00
    Signature49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber02c4d1e58a4a680c568da3047e7e4d5f
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • fwpkclnt.sys
    • NDIS.SYS

    Imported Functions

    Expand
    • KeBugCheckEx
    • ExUuidCreate
    • swprintf_s
    • RtlCreateSecurityDescriptor
    • RtlLengthSid
    • IoAllocateMdl
    • ObOpenObjectByPointer
    • IoReleaseCancelSpinLock
    • IoCreateDevice
    • MmFreePagesFromMdl
    • ObfDereferenceObject
    • PsGetCurrentProcessId
    • IoCreateSymbolicLink
    • SeExports
    • ZwSetSecurityObject
    • KeWaitForSingleObject
    • ObReferenceObjectByHandle
    • ZwSetInformationThread
    • IofCompleteRequest
    • PsTerminateSystemThread
    • ZwQueryValueKey
    • MmMapLockedPagesSpecifyCache
    • PsCreateSystemThread
    • RtlAddAccessAllowedAce
    • MmBuildMdlForNonPagedPool
    • MmAllocatePagesForMdl
    • KeInitializeEvent
    • RtlAppendUnicodeToString
    • MmGetSystemRoutineAddress
    • KeSetEvent
    • IoDeleteDevice
    • RtlSetDaclSecurityDescriptor
    • PsLookupProcessByProcessId
    • RtlCreateAcl
    • IoDeleteSymbolicLink
    • MmUnmapLockedPages
    • ExDeleteNPagedLookasideList
    • ExQueryDepthSList
    • IoFreeMdl
    • ExpInterlockedPopEntrySList
    • KeAcquireInStackQueuedSpinLock
    • ExpInterlockedPushEntrySList
    • KeReleaseInStackQueuedSpinLock
    • ExInitializeNPagedLookasideList
    • ExFreePoolWithTag
    • ExAllocatePoolWithTag
    • ZwOpenKey
    • ZwClose
    • RtlInitUnicodeString
    • __C_specific_handler
    • FwpsFlowAssociateContext0
    • FwpsCalloutUnregisterByKey0
    • FwpmSubLayerAdd0
    • FwpsQueryPacketInjectionState0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerEnum0
    • FwpmTransactionCommit0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmProviderContextDeleteByKey0
    • FwpmCalloutAdd0
    • FwpmProviderAdd0
    • FwpmTransactionAbort0
    • FwpmEngineOpen0
    • FwpsAcquireClassifyHandle0
    • FwpmFilterAdd0
    • FwpsPendClassify0
    • FwpsCalloutRegister1
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmFreeMemory0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsFreeCloneNetBufferList0
    • FwpsInjectionHandleDestroy0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsAllocateNetBufferAndNetBufferList0
    • FwpsInjectionHandleCreate0
    • FwpsInjectTransportReceiveAsync0
    • FwpsInjectNetworkSendAsync0
    • FwpsCopyStreamDataToBuffer0
    • FwpsInjectTransportSendAsync0
    • FwpsFlowRemoveContext0
    • FwpsCloneStreamData0
    • FwpsCompleteClassify0
    • FwpsStreamInjectAsync0
    • FwpsReleaseClassifyHandle0
    • FwpsDiscardClonedStreamData0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • FwpmBfeStateUnsubscribeChanges0
    • FwpsFreeNetBufferList0
    • NdisAllocateGenericObject
    • NdisWaitEvent
    • NdisAllocateNetBufferListPool
    • NdisInitializeEvent
    • NdisFreeGenericObject
    • NdisFreeNetBufferListPool
    • NdisGetDataBuffer
    • NdisRetreatNetBufferDataStart
    • NdisAdvanceNetBufferDataStart

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2019-06-10 08:45:55
    MD55c7d08cafbb96b0812a90ce4de52869a
    SHA1eff9b9458f4eb611478a0c959f156f3dc7e62c08
    SHA25679e7165e626c7bde546cd1bea4b9ec206de8bed7821479856bdb0a2adc3e3617
    Authentihash MD5ddbb824860937add7c0f86c5df993d3a
    Authentihash SHA103f0dd3124ec3a4bb6d30865a488f54e74ded699
    Authentihash SHA256dfaefd06b680f9ea837e7815fc1cc7d1f4cc375641ac850667ab20739f46ad22
    RichPEHeaderHash MD5a8cfc1c4c595dbd9909445a5e7ed9a54
    RichPEHeaderHash SHA193a8f9bf4e4c8886fc1d435828ab6706d11cfdf9
    RichPEHeaderHash SHA256dd65f865e9c50e9dde3584d90f0927d21042665aa375918708b4792861041072
    Company宏图无忧
    DescriptionWYJSQ TDI Hook Driver (WPP)
    Product无忧加速器驱动文件
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 09450b8f73ea43e39d2cdd56049dbe40
    FieldValue
    ToBeSigned (TBS) MD5bcfecc67375f580ac6eadd789860b1f8
    ToBeSigned (TBS) SHA13fa9cf13a1816a6e358bb1ca12e050662bc2e178
    ToBeSigned (TBS) SHA256fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df
    SubjectC=CN, ST=, L=, O=, CN=
    ValidFrom2019-06-27 00:00:00
    ValidTo2020-06-30 12:00:00
    Signature03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber09450b8f73ea43e39d2cdd56049dbe40
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 02c4d1e58a4a680c568da3047e7e4d5f
    FieldValue
    ToBeSigned (TBS) MD5829995f702421dea833a24fb2c7f4442
    ToBeSigned (TBS) SHA11d7e838accd498c2e5ba9373af819ec097bb955c
    ToBeSigned (TBS) SHA25692914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1
    ValidFrom2011-02-11 12:00:00
    ValidTo2026-02-10 12:00:00
    Signature49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber02c4d1e58a4a680c568da3047e7e4d5f
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • TDI.SYS

    Imported Functions

    Expand
    • KeReleaseSpinLock
    • KeAcquireSpinLockRaiseToDpc
    • IoDeleteSymbolicLink
    • PsLookupProcessByProcessId
    • RtlInitUnicodeString
    • IoDeleteDevice
    • MmGetSystemRoutineAddress
    • ZwClose
    • IofCompleteRequest
    • IoCreateSymbolicLink
    • ObfDereferenceObject
    • IoCreateDevice
    • ObOpenObjectByPointer
    • IofCallDriver
    • IoDetachDevice
    • IoBuildDeviceIoControlRequest
    • RtlDowncaseUnicodeString
    • KeInitializeEvent
    • MmBuildMdlForNonPagedPool
    • IoFreeMdl
    • KeInsertQueueDpc
    • KeWaitForSingleObject
    • PsGetCurrentProcessId
    • IoAllocateMdl
    • ExFreePoolWithTag
    • IoFreeIrp
    • IoReleaseCancelSpinLock
    • MmMapLockedPagesSpecifyCache
    • IoAllocateIrp
    • KeInitializeTimer
    • RtlAppendUnicodeToString
    • KeInitializeDpc
    • IoGetDeviceObjectPointer
    • IoAttachDeviceToDeviceStack
    • KeSetTimer
    • ObfReferenceObject
    • MmFreePagesFromMdl
    • MmUnmapLockedPages
    • MmAllocatePagesForMdl
    • RtlCreateAcl
    • RtlSetDaclSecurityDescriptor
    • RtlAddAccessAllowedAce
    • ZwQueryValueKey
    • ZwSetSecurityObject
    • SeExports
    • RtlLengthSid
    • RtlCreateSecurityDescriptor
    • ZwOpenKey
    • KeBugCheckEx
    • ObReferenceObjectByHandle
    • ExAllocatePoolWithTag
    • __C_specific_handler
    • TdiMapUserRequest

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2019-06-10 08:45:52
    MD5546107a0f37686b2417f1be2e05305f6
    SHA1b06af934021f48fa31db5759fa1eafa1927fc7e5
    SHA2566a234a2b8eb3844f7b5831ee048f88e8a76e9d38e753cc82f61b234c79fe1660
    Authentihash MD5b42afd5a5225094c7943185e769bc995
    Authentihash SHA122c5e127e7e7c567d8624607a6f8f5809deacb55
    Authentihash SHA256de6bf572d39e2611773e7a01f0388f84fb25da6cba2f1f8b9b36ffba467de6fa
    RichPEHeaderHash MD5ea1a25e78d69ef318ef4d2fbfd420541
    RichPEHeaderHash SHA11f795bc5eaecf5ee96f77ae703426b5f65e0d895
    RichPEHeaderHash SHA2561c10422043879162a1e9a246a3125f545a119afc8c25fd6822f48509ee2a02c0
    Company宏图无忧
    DescriptionWYJSQ TDI Hook Driver (WPP)
    Product无忧加速器
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 09450b8f73ea43e39d2cdd56049dbe40
    FieldValue
    ToBeSigned (TBS) MD5bcfecc67375f580ac6eadd789860b1f8
    ToBeSigned (TBS) SHA13fa9cf13a1816a6e358bb1ca12e050662bc2e178
    ToBeSigned (TBS) SHA256fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df
    SubjectC=CN, ST=, L=, O=, CN=
    ValidFrom2019-06-27 00:00:00
    ValidTo2020-06-30 12:00:00
    Signature03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber09450b8f73ea43e39d2cdd56049dbe40
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 02c4d1e58a4a680c568da3047e7e4d5f
    FieldValue
    ToBeSigned (TBS) MD5829995f702421dea833a24fb2c7f4442
    ToBeSigned (TBS) SHA11d7e838accd498c2e5ba9373af819ec097bb955c
    ToBeSigned (TBS) SHA25692914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1
    ValidFrom2011-02-11 12:00:00
    ValidTo2026-02-10 12:00:00
    Signature49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber02c4d1e58a4a680c568da3047e7e4d5f
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll
    • TDI.SYS

    Imported Functions

    Expand
    • IoCreateSymbolicLink
    • IoCreateDevice
    • IoDeleteSymbolicLink
    • IofCompleteRequest
    • ZwClose
    • ObfDereferenceObject
    • ObOpenObjectByPointer
    • PsLookupProcessByProcessId
    • MmGetSystemRoutineAddress
    • RtlInitUnicodeString
    • IoDetachDevice
    • IofCallDriver
    • IoFreeMdl
    • memcpy
    • MmBuildMdlForNonPagedPool
    • IoBuildDeviceIoControlRequest
    • IoAllocateMdl
    • RtlDowncaseUnicodeString
    • PsGetCurrentProcessId
    • KeWaitForSingleObject
    • KeInitializeEvent
    • KeInsertQueueDpc
    • IoReleaseCancelSpinLock
    • ObReferenceObjectByHandle
    • IoDeleteDevice
    • MmMapLockedPagesSpecifyCache
    • IoAllocateIrp
    • KeInitializeTimer
    • KeInitializeDpc
    • RtlAppendUnicodeToString
    • IoAttachDeviceToDeviceStack
    • IoGetDeviceObjectPointer
    • ObfReferenceObject
    • KeSetTimer
    • MmFreePagesFromMdl
    • MmUnmapLockedPages
    • MmAllocatePagesForMdl
    • ZwQueryValueKey
    • ZwOpenKey
    • ZwSetSecurityObject
    • RtlSetDaclSecurityDescriptor
    • RtlCreateSecurityDescriptor
    • RtlAddAccessAllowedAce
    • RtlCreateAcl
    • RtlLengthSid
    • SeExports
    • KeTickCount
    • KeBugCheckEx
    • _aullrem
    • ExFreePoolWithTag
    • memset
    • IoFreeIrp
    • ExAllocatePoolWithTag
    • RtlUnwind
    • KfAcquireSpinLock
    • KfReleaseSpinLock
    • TdiMapUserRequest

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2020-09-15 00:54:19
    MD5dc83a482d5900f19c0b92b9d183449ed
    SHA1d219edc08fb789817c264b164f3034543b6a2e08
    SHA2565c54a5cd3386ac14725a07962562e9fdcefbb7be0d19803f9d71de24573de1e3
    Authentihash MD50d76526227d593a8967ed866b5991e10
    Authentihash SHA13ae56ab63230d6d9552360845b4a37b5801cc5ea
    Authentihash SHA256e9b433a33dc72eb2622947b41f01d04a48cd71beac775a88f3f1e4c838090ee8
    RichPEHeaderHash MD55f9eb581b0ce6f9d2b5f1f5a9771af50
    RichPEHeaderHash SHA1cb1828152e4668b5e033ee126a52df4f76700b2a
    RichPEHeaderHash SHA256e9bd3b71a475097efee5f9196d05a582abc2323affe47c2c9cf9bf933004e22f
    CompanyWindows (R) Win 7 DDK provider
    DescriptionNetFilter SDK WFP Driver (WPP)
    ProductWindows (R) Win 7 DDK driver
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 0af5efac8e1cb5bb290394d315079dbe
    FieldValue
    ToBeSigned (TBS) MD511e15766710ca8d294dcaf75cdc481c7
    ToBeSigned (TBS) SHA1d4fbc4f59e8ac285a2a1cdde885eab8ec7c073f2
    ToBeSigned (TBS) SHA2568235db8c900fcefb648b477bd93a19628b36ff95f3c53237eeae5d3dc6edb450
    Subject??=CN, ??=, ??=, ??=Private Organization, serialNumber=91330701MA28DMHT4Y, C=CN, ST=, L=, O=, CN=
    ValidFrom2019-03-22 00:00:00
    ValidTo2021-03-25 12:00:00
    Signature5e1cb6b58ffb591e3a704dc59756f1ecc243200154b08df383197a63b507099accf1fb5302f3868ccebd3057fbab16d7a9bdcf143a9502d3489e7f673d0fd81c4feb5f98561f7c0971d93ed826da97dbd0622d55a14be6cffd7c18b7668fb800afba5c12037b1d673409daf19e06dc378ff0da81facc1c3d85f5f740a83a01c1ab827c9fe78ef252f1e8f0d91eb9d231f88f155d5571ca01bc222a1e6efedd466d2fab104e7eb1d390df00fc22e006ff9d5291b720faa6b907f8e5440b2f6b3284fc4e91c9c16a2ab3ccc977f147709117e1d97824663e55602037259f03488ce6f6ab82476b2ff21df0351d53690bb404bff4c78f419ab59b10e97751c5442d
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber0af5efac8e1cb5bb290394d315079dbe
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 0dd0e3374ac95bdbfa6b434b2a48ec06
    FieldValue
    ToBeSigned (TBS) MD5f92649915476229b093c211c2b18e6c4
    ToBeSigned (TBS) SHA12d54c16a8f8b69ccdea48d0603c132f547a5cf75
    ToBeSigned (TBS) SHA2562cd702a7dec30aa441345672e8992ef9770ce4946f276d767b45b0ed627658fb
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert EV Code Signing CA
    ValidFrom2012-04-18 12:00:00
    ValidTo2027-04-18 12:00:00
    Signature9e5b963a2e1288acab016da49f75e40187a3a532d7bcbaa97ea3d61417f7c2136b7c738f2b6ae50f265968b08e259b6ceffa6c939208c14dcf459e9c46d61e74a19b14a3fa012f4ab101e1724048111368b9369d914bd7c2391210c1c4dcbb6214142a615d4f387c661fc61bffadbe4f7f945b7343000f4d73b751cf0ef677c05bcd348cd96313aa0e6111d6f28e27fcb47bb8b91120918678ea0ed428ff2ad52438e837b2ec96bb9fbc4a1650e15ebf517d23a032c7c1949e7ac9c026a2cc2587a0127e749f2d8db1c8e784beb9d1e9debb6a4e887371e12238cb2487e9737e51b2ff98eb4e7e2fe0ca0efab35ed1ba0542a8489f83f63fc4caa8df68a05061
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber0dd0e3374ac95bdbfa6b434b2a48ec06
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • fwpkclnt.sys
    • NDIS.SYS

    Imported Functions

    Expand
    • KeBugCheckEx
    • ExUuidCreate
    • swprintf_s
    • RtlCreateSecurityDescriptor
    • RtlLengthSid
    • IoAllocateMdl
    • ObOpenObjectByPointer
    • IoReleaseCancelSpinLock
    • IoCreateDevice
    • MmFreePagesFromMdl
    • ObfDereferenceObject
    • PsGetCurrentProcessId
    • IoCreateSymbolicLink
    • SeExports
    • ZwSetSecurityObject
    • KeWaitForSingleObject
    • ObReferenceObjectByHandle
    • ZwSetInformationThread
    • IofCompleteRequest
    • PsTerminateSystemThread
    • ZwQueryValueKey
    • MmMapLockedPagesSpecifyCache
    • PsCreateSystemThread
    • RtlAddAccessAllowedAce
    • MmBuildMdlForNonPagedPool
    • MmAllocatePagesForMdl
    • KeInitializeEvent
    • RtlAppendUnicodeToString
    • MmGetSystemRoutineAddress
    • KeSetEvent
    • IoDeleteDevice
    • RtlSetDaclSecurityDescriptor
    • PsLookupProcessByProcessId
    • RtlCreateAcl
    • IoDeleteSymbolicLink
    • MmUnmapLockedPages
    • RtlCompareMemory
    • RtlValidSid
    • ExDeleteNPagedLookasideList
    • ExQueryDepthSList
    • IoFreeMdl
    • ExpInterlockedPopEntrySList
    • KeAcquireInStackQueuedSpinLock
    • ExpInterlockedPushEntrySList
    • KeReleaseInStackQueuedSpinLock
    • ExInitializeNPagedLookasideList
    • ExFreePoolWithTag
    • ExAllocatePoolWithTag
    • ZwOpenKey
    • ZwClose
    • RtlInitUnicodeString
    • __C_specific_handler
    • FwpsFlowAssociateContext0
    • FwpsCalloutUnregisterByKey0
    • FwpmSubLayerAdd0
    • FwpsQueryPacketInjectionState0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerEnum0
    • FwpmTransactionCommit0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmProviderContextDeleteByKey0
    • FwpmCalloutAdd0
    • FwpmProviderAdd0
    • FwpmTransactionAbort0
    • FwpmEngineOpen0
    • FwpsAcquireClassifyHandle0
    • FwpmFilterAdd0
    • FwpsPendClassify0
    • FwpsCalloutRegister1
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmFreeMemory0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsFreeCloneNetBufferList0
    • FwpsInjectionHandleDestroy0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsAllocateNetBufferAndNetBufferList0
    • FwpsInjectionHandleCreate0
    • FwpsInjectTransportReceiveAsync0
    • FwpsInjectNetworkSendAsync0
    • FwpsCopyStreamDataToBuffer0
    • FwpsInjectTransportSendAsync0
    • FwpsFlowRemoveContext0
    • FwpsCloneStreamData0
    • FwpsCompleteClassify0
    • FwpsStreamInjectAsync0
    • FwpsReleaseClassifyHandle0
    • FwpsDiscardClonedStreamData0
    • FwpsFreeNetBufferList0
    • FwpmBfeStateUnsubscribeChanges0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • NdisAllocateGenericObject
    • NdisWaitEvent
    • NdisAllocateNetBufferListPool
    • NdisInitializeEvent
    • NdisFreeGenericObject
    • NdisFreeNetBufferListPool
    • NdisGetDataBuffer
    • NdisRetreatNetBufferDataStart
    • NdisAdvanceNetBufferDataStart

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2020-09-15 00:54:17
    MD51b54c047e17f0319a6202b579a850c54
    SHA1d1178492ba5e23927141fa49edb9aa29640f20f8
    SHA2568017e618b5a7aa608cc4bce16e4defd6b4e99138c4ba1bdd6ad78e39f035cf59
    Authentihash MD56d4517e6348130fe55f11bfd630d857f
    Authentihash SHA160a632e4b838731aad553650d6bc8af3d3d80b26
    Authentihash SHA2568168304169a2453c0c3e0a285c2a07d3b3b83433e0342f6b33400c371af86221
    RichPEHeaderHash MD54c93d23c41f384b75bda01c7ace495d8
    RichPEHeaderHash SHA128695a10b02de9e1ce2d2b70c463f5d3bbaeaf4c
    RichPEHeaderHash SHA2564049be109d3e76b72f97f3faab4a4456933bce7ec4593342fd7046ca2bae226e
    CompanyWindows (R) Win 7 DDK provider
    DescriptionNetFilter SDK WFP Driver (WPP)
    ProductWindows (R) Win 7 DDK driver
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 34b2bc04e9d297465f2e52b3afe91006
    FieldValue
    ToBeSigned (TBS) MD5aa18d17697a27f7af6deb97095af2a2c
    ToBeSigned (TBS) SHA1d00a8a47f4879d72d0c724fe76c98c509406169f
    ToBeSigned (TBS) SHA256b17c8db0c54e42683d417a0908ba35d55ee44ad152024e2b178aa2a903cc385b
    SubjectC=FR, L=Paris, O=Orange, OU=Nordnet, CN=Orange
    ValidFrom2020-02-06 00:00:00
    ValidTo2021-02-06 23:59:59
    Signature69bcb684fce97d7337f96fc6fe53b0ea3583530177b86a8e2986a25d33f46573718cd139b90876b9ed26317dcbf2d305846428eef0886a0e824a5351b9ae4f53b40ca53331e027951ad1808cbfd74c8376455c69ed4d0087339d3d42c3111d958795c33007f0b0a71ab19e720b5a47e01474041e4fd44845d5970d51b2163299b22b092c5bc35bfa3f11c357ca0d5fcd5359d02e8dc44f89a5720383accd5eb0c206e222ddae0f3840043da2432c644e29a4daeb3d8478adda02ee49e677e3327aecf41ecfef68a311c976b0f2b1e96101d8a332c02df2f34a954f4542bfc8ef3dbe237e731fd501b7097ae5692f5b0cc33cce4e84874d2d37deaa324d5ec72e
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber34b2bc04e9d297465f2e52b3afe91006
    Version3
    Certificate 3d78d7f9764960b2617df4f01eca862a
    FieldValue
    ToBeSigned (TBS) MD51f056ff7d5f874984dc605402b7cb042
    ToBeSigned (TBS) SHA1bdb348353a2203deb4b767914fa1bd7248dd728b
    ToBeSigned (TBS) SHA256a08e79c386083d875014c409c13d144e0a24386132980df11ff59737c8489eb1
    SubjectC=US, O=Symantec Corporation, OU=Symantec Trust Network, CN=Symantec Class 3 SHA256 Code Signing CA
    ValidFrom2013-12-10 00:00:00
    ValidTo2023-12-09 23:59:59
    Signature13851a1e69a937f7a0bda4af7e1d6153fe9d8c5e0ca6751e781723ddfdec1a035539fb7195c7655aa78e30d2445a61db706fda2105c22e73ba49f1d193fe5dc9cd5e03e0899e3f741ed7f7388ba9d6cfbb352f3358a89256d1c84d3b82e6798416fc28b0b147f31da23eee87d9a67fa456a53fad842e29de7cbca8aaa33d0401eaba93a20e502229174c87e43a115fd6a425899b056b2fb4c9014c277b0bac190522a060153fdac9fb4d4c8ffb726777fd2794c7ba350e8849fe8dfd28af4a12bd0db39705de440c15fa362b03dcc15001f1a1115d14e5e2bd274b54be2b845e0fa6c374050aef97c38922b11f77f3bdcd43d4f14ca93fb58b84af64f2d01421
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber3d78d7f9764960b2617df4f01eca862a
    Version3
    Certificate 611993e400000000001c
    FieldValue
    ToBeSigned (TBS) MD578a717e082dcc1cda3458d917e677d14
    ToBeSigned (TBS) SHA14a872e0e51f9b304469cd1dedb496ee9b8b983a4
    ToBeSigned (TBS) SHA256317fa1d234ebc49040ebc5e8746f8997471496051b185a91bdd9dfbb23fab5f8
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. , For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority , G5
    ValidFrom2011-02-22 19:25:17
    ValidTo2021-02-22 19:35:17
    Signature812a82168c34672be503eb347b8ca2a3508af45586f11e8c8eae7dee0319ce72951848ad6211fd20fd3f4706015ae2e06f8c152c4e3c6a506c0b36a3cf7a0d9c42bc5cf819d560e369e6e22341678c6883762b8f93a32ab57fbe59fba9c9b2268fcaa2f3821b983e919527978661ee5b5d076bcd86a8e26580a8e215e2b2be23056aba0cf347934daca48c077939c061123a050d89a3ec9f578984fbecca7c47661491d8b60f195de6b84aacbc47c8714396e63220a5dc7786fd3ce38b71db7b9b03fcb71d3264eb1652a043a3fa2ead59924e7cc7f233424838513a7c38c71b242228401e1a461f17db18f7f027356cb863d9cdb9645d2ba55eefc629b4f2c7f821cc04ba57fd01b6abc667f9e7d3997ff4f522fa72f5fdff3a1c423aa1f98018a5ee8d1cd4669e4501feaaeefffb178f30f7f1cd29c59decb5d549003d85b8cbbb933a276a49c030ae66c9f723283276f9a48356c848ce5a96aaa0cc0cc47fb48e97af6de35427c39f86c0d6e473089705dbd054625e0348c2d59f7fa7668cd09db04fd4d3985f4b7ac97fb22952d01280c70f54b61e67cdc6a06c110384d34875e72afeb03b6e0a3aa66b769905a3f177686133144706fc537f52bd92145c4a246a678caf8d90aad0f679211b93267cc3ce1ebd883892ae45c6196a4950b305f8ae59378a6a250394b1598150e8ba8380b72335f476b9671d5918ad208d94
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber611993e400000000001c
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll
    • fwpkclnt.sys
    • NDIS.SYS

    Imported Functions

    Expand
    • memcpy
    • RtlValidSid
    • IoFreeMdl
    • RtlUnwind
    • KeBugCheckEx
    • RtlCompareMemory
    • KeTickCount
    • _allmul
    • _aulldiv
    • KeQuerySystemTime
    • ExUuidCreate
    • swprintf_s
    • KeInitializeEvent
    • PsCreateSystemThread
    • ZwSetInformationThread
    • ObReferenceObjectByHandle
    • RtlAppendUnicodeToString
    • IoCreateDevice
    • IoCreateSymbolicLink
    • PsTerminateSystemThread
    • MmGetSystemRoutineAddress
    • PsLookupProcessByProcessId
    • IoAllocateMdl
    • MmBuildMdlForNonPagedPool
    • IoReleaseCancelSpinLock
    • PsGetCurrentProcessId
    • IofCompleteRequest
    • IoDeleteSymbolicLink
    • IoDeleteDevice
    • KeWaitForSingleObject
    • ObfDereferenceObject
    • MmAllocatePagesForMdl
    • MmMapLockedPagesSpecifyCache
    • MmFreePagesFromMdl
    • MmUnmapLockedPages
    • KeSetEvent
    • ObOpenObjectByPointer
    • RtlLengthSid
    • SeExports
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • ZwSetSecurityObject
    • ZwQueryValueKey
    • ExDeleteNPagedLookasideList
    • ExInitializeNPagedLookasideList
    • InterlockedPushEntrySList
    • InterlockedPopEntrySList
    • _aullrem
    • ExFreePoolWithTag
    • memset
    • ExAllocatePoolWithTag
    • RtlInitUnicodeString
    • ZwOpenKey
    • ZwClose
    • KeReleaseInStackQueuedSpinLock
    • KeGetCurrentIrql
    • KeAcquireInStackQueuedSpinLock
    • FwpsStreamInjectAsync0
    • FwpmEngineOpen0
    • FwpmProviderAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmProviderContextDeleteByKey0
    • FwpsAcquireClassifyHandle0
    • FwpsQueryPacketInjectionState0
    • FwpsFlowAssociateContext0
    • FwpmSubLayerAdd0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmFreeMemory0
    • FwpmSubLayerEnum0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmCalloutAdd0
    • FwpmFilterAdd0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmTransactionCommit0
    • FwpmTransactionAbort0
    • FwpsCalloutRegister1
    • FwpsCalloutUnregisterByKey0
    • FwpsPendClassify0
    • FwpsInjectionHandleCreate0
    • FwpsCopyStreamDataToBuffer0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpsAllocateNetBufferAndNetBufferList0
    • FwpsInjectTransportSendAsync0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsInjectNetworkSendAsync0
    • FwpsInjectTransportReceiveAsync0
    • FwpsFreeCloneNetBufferList0
    • FwpsInjectionHandleDestroy0
    • FwpsFlowRemoveContext0
    • FwpsCloneStreamData0
    • FwpsCompleteClassify0
    • FwpsReleaseClassifyHandle0
    • FwpsDiscardClonedStreamData0
    • FwpsFreeNetBufferList0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • FwpmBfeStateUnsubscribeChanges0
    • NdisFreeGenericObject
    • NdisInitializeEvent
    • NdisFreeNetBufferListPool
    • NdisGetDataBuffer
    • NdisAdvanceNetBufferDataStart
    • NdisRetreatNetBufferDataStart
    • NdisAllocateNetBufferListPool
    • NdisAllocateGenericObject
    • NdisWaitEvent

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2020-09-15 00:54:19
    MD514acd57bd9fa8093c46fdd5e9f271b70
    SHA1b0cb07e84261626a384e74020735be0cace7a3bd
    SHA256639ff79f13e40d47b90ecd709699edd10e740cb41451acb95590a68b6352de2b
    Authentihash MD50d76526227d593a8967ed866b5991e10
    Authentihash SHA13ae56ab63230d6d9552360845b4a37b5801cc5ea
    Authentihash SHA256e9b433a33dc72eb2622947b41f01d04a48cd71beac775a88f3f1e4c838090ee8
    RichPEHeaderHash MD55f9eb581b0ce6f9d2b5f1f5a9771af50
    RichPEHeaderHash SHA1cb1828152e4668b5e033ee126a52df4f76700b2a
    RichPEHeaderHash SHA256e9bd3b71a475097efee5f9196d05a582abc2323affe47c2c9cf9bf933004e22f
    CompanyWindows (R) Win 7 DDK provider
    DescriptionNetFilter SDK WFP Driver (WPP)
    ProductWindows (R) Win 7 DDK driver
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 34b2bc04e9d297465f2e52b3afe91006
    FieldValue
    ToBeSigned (TBS) MD5aa18d17697a27f7af6deb97095af2a2c
    ToBeSigned (TBS) SHA1d00a8a47f4879d72d0c724fe76c98c509406169f
    ToBeSigned (TBS) SHA256b17c8db0c54e42683d417a0908ba35d55ee44ad152024e2b178aa2a903cc385b
    SubjectC=FR, L=Paris, O=Orange, OU=Nordnet, CN=Orange
    ValidFrom2020-02-06 00:00:00
    ValidTo2021-02-06 23:59:59
    Signature69bcb684fce97d7337f96fc6fe53b0ea3583530177b86a8e2986a25d33f46573718cd139b90876b9ed26317dcbf2d305846428eef0886a0e824a5351b9ae4f53b40ca53331e027951ad1808cbfd74c8376455c69ed4d0087339d3d42c3111d958795c33007f0b0a71ab19e720b5a47e01474041e4fd44845d5970d51b2163299b22b092c5bc35bfa3f11c357ca0d5fcd5359d02e8dc44f89a5720383accd5eb0c206e222ddae0f3840043da2432c644e29a4daeb3d8478adda02ee49e677e3327aecf41ecfef68a311c976b0f2b1e96101d8a332c02df2f34a954f4542bfc8ef3dbe237e731fd501b7097ae5692f5b0cc33cce4e84874d2d37deaa324d5ec72e
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber34b2bc04e9d297465f2e52b3afe91006
    Version3
    Certificate 3d78d7f9764960b2617df4f01eca862a
    FieldValue
    ToBeSigned (TBS) MD51f056ff7d5f874984dc605402b7cb042
    ToBeSigned (TBS) SHA1bdb348353a2203deb4b767914fa1bd7248dd728b
    ToBeSigned (TBS) SHA256a08e79c386083d875014c409c13d144e0a24386132980df11ff59737c8489eb1
    SubjectC=US, O=Symantec Corporation, OU=Symantec Trust Network, CN=Symantec Class 3 SHA256 Code Signing CA
    ValidFrom2013-12-10 00:00:00
    ValidTo2023-12-09 23:59:59
    Signature13851a1e69a937f7a0bda4af7e1d6153fe9d8c5e0ca6751e781723ddfdec1a035539fb7195c7655aa78e30d2445a61db706fda2105c22e73ba49f1d193fe5dc9cd5e03e0899e3f741ed7f7388ba9d6cfbb352f3358a89256d1c84d3b82e6798416fc28b0b147f31da23eee87d9a67fa456a53fad842e29de7cbca8aaa33d0401eaba93a20e502229174c87e43a115fd6a425899b056b2fb4c9014c277b0bac190522a060153fdac9fb4d4c8ffb726777fd2794c7ba350e8849fe8dfd28af4a12bd0db39705de440c15fa362b03dcc15001f1a1115d14e5e2bd274b54be2b845e0fa6c374050aef97c38922b11f77f3bdcd43d4f14ca93fb58b84af64f2d01421
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber3d78d7f9764960b2617df4f01eca862a
    Version3
    Certificate 611993e400000000001c
    FieldValue
    ToBeSigned (TBS) MD578a717e082dcc1cda3458d917e677d14
    ToBeSigned (TBS) SHA14a872e0e51f9b304469cd1dedb496ee9b8b983a4
    ToBeSigned (TBS) SHA256317fa1d234ebc49040ebc5e8746f8997471496051b185a91bdd9dfbb23fab5f8
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. , For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority , G5
    ValidFrom2011-02-22 19:25:17
    ValidTo2021-02-22 19:35:17
    Signature812a82168c34672be503eb347b8ca2a3508af45586f11e8c8eae7dee0319ce72951848ad6211fd20fd3f4706015ae2e06f8c152c4e3c6a506c0b36a3cf7a0d9c42bc5cf819d560e369e6e22341678c6883762b8f93a32ab57fbe59fba9c9b2268fcaa2f3821b983e919527978661ee5b5d076bcd86a8e26580a8e215e2b2be23056aba0cf347934daca48c077939c061123a050d89a3ec9f578984fbecca7c47661491d8b60f195de6b84aacbc47c8714396e63220a5dc7786fd3ce38b71db7b9b03fcb71d3264eb1652a043a3fa2ead59924e7cc7f233424838513a7c38c71b242228401e1a461f17db18f7f027356cb863d9cdb9645d2ba55eefc629b4f2c7f821cc04ba57fd01b6abc667f9e7d3997ff4f522fa72f5fdff3a1c423aa1f98018a5ee8d1cd4669e4501feaaeefffb178f30f7f1cd29c59decb5d549003d85b8cbbb933a276a49c030ae66c9f723283276f9a48356c848ce5a96aaa0cc0cc47fb48e97af6de35427c39f86c0d6e473089705dbd054625e0348c2d59f7fa7668cd09db04fd4d3985f4b7ac97fb22952d01280c70f54b61e67cdc6a06c110384d34875e72afeb03b6e0a3aa66b769905a3f177686133144706fc537f52bd92145c4a246a678caf8d90aad0f679211b93267cc3ce1ebd883892ae45c6196a4950b305f8ae59378a6a250394b1598150e8ba8380b72335f476b9671d5918ad208d94
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber611993e400000000001c
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • fwpkclnt.sys
    • NDIS.SYS

    Imported Functions

    Expand
    • KeBugCheckEx
    • ExUuidCreate
    • swprintf_s
    • RtlCreateSecurityDescriptor
    • RtlLengthSid
    • IoAllocateMdl
    • ObOpenObjectByPointer
    • IoReleaseCancelSpinLock
    • IoCreateDevice
    • MmFreePagesFromMdl
    • ObfDereferenceObject
    • PsGetCurrentProcessId
    • IoCreateSymbolicLink
    • SeExports
    • ZwSetSecurityObject
    • KeWaitForSingleObject
    • ObReferenceObjectByHandle
    • ZwSetInformationThread
    • IofCompleteRequest
    • PsTerminateSystemThread
    • ZwQueryValueKey
    • MmMapLockedPagesSpecifyCache
    • PsCreateSystemThread
    • RtlAddAccessAllowedAce
    • MmBuildMdlForNonPagedPool
    • MmAllocatePagesForMdl
    • KeInitializeEvent
    • RtlAppendUnicodeToString
    • MmGetSystemRoutineAddress
    • KeSetEvent
    • IoDeleteDevice
    • RtlSetDaclSecurityDescriptor
    • PsLookupProcessByProcessId
    • RtlCreateAcl
    • IoDeleteSymbolicLink
    • MmUnmapLockedPages
    • RtlCompareMemory
    • RtlValidSid
    • ExDeleteNPagedLookasideList
    • ExQueryDepthSList
    • IoFreeMdl
    • ExpInterlockedPopEntrySList
    • KeAcquireInStackQueuedSpinLock
    • ExpInterlockedPushEntrySList
    • KeReleaseInStackQueuedSpinLock
    • ExInitializeNPagedLookasideList
    • ExFreePoolWithTag
    • ExAllocatePoolWithTag
    • ZwOpenKey
    • ZwClose
    • RtlInitUnicodeString
    • __C_specific_handler
    • FwpsFlowAssociateContext0
    • FwpsCalloutUnregisterByKey0
    • FwpmSubLayerAdd0
    • FwpsQueryPacketInjectionState0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerEnum0
    • FwpmTransactionCommit0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmProviderContextDeleteByKey0
    • FwpmCalloutAdd0
    • FwpmProviderAdd0
    • FwpmTransactionAbort0
    • FwpmEngineOpen0
    • FwpsAcquireClassifyHandle0
    • FwpmFilterAdd0
    • FwpsPendClassify0
    • FwpsCalloutRegister1
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmFreeMemory0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsFreeCloneNetBufferList0
    • FwpsInjectionHandleDestroy0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsAllocateNetBufferAndNetBufferList0
    • FwpsInjectionHandleCreate0
    • FwpsInjectTransportReceiveAsync0
    • FwpsInjectNetworkSendAsync0
    • FwpsCopyStreamDataToBuffer0
    • FwpsInjectTransportSendAsync0
    • FwpsFlowRemoveContext0
    • FwpsCloneStreamData0
    • FwpsCompleteClassify0
    • FwpsStreamInjectAsync0
    • FwpsReleaseClassifyHandle0
    • FwpsDiscardClonedStreamData0
    • FwpsFreeNetBufferList0
    • FwpmBfeStateUnsubscribeChanges0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • NdisAllocateGenericObject
    • NdisWaitEvent
    • NdisAllocateNetBufferListPool
    • NdisInitializeEvent
    • NdisFreeGenericObject
    • NdisFreeNetBufferListPool
    • NdisGetDataBuffer
    • NdisRetreatNetBufferDataStart
    • NdisAdvanceNetBufferDataStart

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2020-09-15 00:54:41
    MD5303d0cc0864955eb20fe820104713d5f
    SHA122314679389c9db6e7e99ca991a597055100f50b
    SHA2569dbc2a37f53507296cc912e7d354dab4e55541ba821561aa84f74d1bd8346be2
    Authentihash MD53361957860d2b65c0368778ca088946f
    Authentihash SHA16a784d45517142c11d5cca3ff9956b2ed6eaf4c9
    Authentihash SHA256e94e8a87459db56837d1c58f9854794aa99f36566a9ded9b398be9d4d3a2c2af
    RichPEHeaderHash MD5c646eed94ec9e75c1a5498d3642cdab3
    RichPEHeaderHash SHA10d0761641e424cc895ba76723784427fcf297f4a
    RichPEHeaderHash SHA2567cecb42d3d4ae8649f3b4714fbab29c4cef8e24a48b0eea2537824fc40f4ea7f
    CompanyWindows (R) Win 7 DDK provider
    DescriptionNetFilter SDK WFP Driver (WPP)
    ProductWindows (R) Win 7 DDK driver
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 02ddad01eba5f46cb2deb0f7d2acd0f7
    FieldValue
    ToBeSigned (TBS) MD5cd2b0d085a3d343b08650dca77f6d61a
    ToBeSigned (TBS) SHA1003e7627100a520659381210817e3cc34ffa5787
    ToBeSigned (TBS) SHA256bde895ed82cf5ec3a4e10ade85e43a41f5cfb21683c065fe546e83d4c33aa3f1
    Subject??=RU, ??=Private Organization, serialNumber=1157746204230, C=RU, L=, O=LLC SOLAR SECURITY, CN=LLC SOLAR SECURITY
    ValidFrom2020-06-03 00:00:00
    ValidTo2021-06-08 12:00:00
    Signature6fd8c320ccdfbea394ffe3e5a536d22b119b04398171c2e7c31feaa4df598a48fb61e28462a7b1fb7215b4ec83da74c6594e9aaa87f0933e4d365a1e1eddfbac8da585d070cffc63a6d55ae305a70993206f0280515ebea65d7070138d18f0b6a6c617f10f5e575f86279b77e96b3971a2cae4609014310fe3678ee0c54f12eef32d98966d71a1b79f7cd2d6fc3204bddf04cce38750e7e59d0211ef331e77c88063a708457a651f960ba41356fc23b9c330f2c3b7a493a4f2a17bc5c6690e93a5e5f6884c7dba0b585d045ca6eb12075a8585ebf12c6a65fa69ab85a60695d53e3ef609090eebe61f30fa9f28db665da62915d82ccb07c68e628e1fe2c0499e
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber02ddad01eba5f46cb2deb0f7d2acd0f7
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 03f1b4e15f3a82f1149678b3d7d8475c
    FieldValue
    ToBeSigned (TBS) MD583f5de89f641d0fbf60248e10a7b9534
    ToBeSigned (TBS) SHA1382a73a059a08698d6eb98c87e1b36fc750933a4
    ToBeSigned (TBS) SHA256eec58131dc11cd7f512501b15fdbc6074c603b68ca91f7162d5a042054edb0cf
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert EV Code Signing CA (SHA2)
    ValidFrom2012-04-18 12:00:00
    ValidTo2027-04-18 12:00:00
    Signature19334a0c813337dbad36c9e4c93abbb51b2e7aa2e2f44342179ebf4ea14de1b1dbe981dd9f01f2e488d5e9fe09fd21c1ec5d80d2f0d6c143c2fe772bdbf9d79133ce6cd5b2193be62ed6c9934f88408ecde1f57ef10fc6595672e8eb6a41bd1cd546d57c49ca663815c1bfe091707787dcc98d31c90c29a233ed8de287cd898d3f1bffd5e01a978b7cda6dfba8c6b23a666b7b01b3cdd8a634ec1201ab9558a5c45357a860e6e70212a0b92364a24dbb7c81256421becfee42184397bba53706af4dff26a54d614bec4641b865ceb8799e08960b818c8a3b8fc7998ca32a6e986d5e61c696b78ab9612d93b8eb0e0443d7f5fea6f062d4996aa5c1c1f0649480
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber03f1b4e15f3a82f1149678b3d7d8475c
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • NDIS.SYS
    • ntoskrnl.exe

    Imported Functions

    Expand
    • FwpmFreeMemory0
    • FwpmEngineOpen0
    • FwpmEngineClose0
    • FwpmTransactionBegin0
    • FwpmTransactionCommit0
    • FwpmTransactionAbort0
    • FwpmProviderAdd0
    • FwpmProviderContextDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmSubLayerEnum0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmCalloutAdd0
    • FwpmFilterAdd0
    • FwpsFlowAbort0
    • FwpsInjectionHandleCreate0
    • FwpsInjectionHandleDestroy0
    • FwpsRedirectHandleCreate0
    • FwpsFreeNetBufferList0
    • FwpsFreeCloneNetBufferList0
    • FwpsInjectNetworkSendAsync0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsInjectTransportSendAsync0
    • FwpsInjectTransportReceiveAsync0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsStreamInjectAsync0
    • FwpsCopyStreamDataToBuffer0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • FwpmBfeStateUnsubscribeChanges0
    • FwpsFlowRemoveContext0
    • FwpsCompleteClassify0
    • FwpsRedirectHandleDestroy0
    • FwpsCloneStreamData0
    • FwpsDiscardClonedStreamData0
    • FwpsQueryPacketInjectionState0
    • FwpsApplyModifiedLayerData0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsReleaseClassifyHandle0
    • FwpsAcquireClassifyHandle0
    • FwpsFlowAssociateContext0
    • FwpsCalloutUnregisterByKey0
    • FwpsCalloutRegister1
    • FwpsPendClassify0
    • FwpsAllocateNetBufferAndNetBufferList0
    • NdisFreeNetBufferListPool
    • NdisAllocateNetBufferListPool
    • NdisWaitEvent
    • NdisInitializeEvent
    • NdisFreeGenericObject
    • NdisAllocateGenericObject
    • NdisGetDataBuffer
    • NdisAdvanceNetBufferDataStart
    • NdisRetreatNetBufferDataStart
    • KeAcquireInStackQueuedSpinLock
    • KeReleaseInStackQueuedSpinLock
    • ExAllocatePoolWithTag
    • ExUuidCreate
    • swprintf_s
    • RtlInitUnicodeString
    • MmGetSystemRoutineAddress
    • RtlAppendUnicodeToString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeInitializeEvent
    • KeSetEvent
    • KeWaitForSingleObject
    • KeInitializeSpinLock
    • ExFreePoolWithTag
    • ExQueryDepthSList
    • ExpInterlockedPopEntrySList
    • ExpInterlockedPushEntrySList
    • ExInitializeNPagedLookasideList
    • ExDeleteNPagedLookasideList
    • MmBuildMdlForNonPagedPool
    • MmMapLockedPagesSpecifyCache
    • MmUnmapLockedPages
    • MmAllocatePagesForMdl
    • MmFreePagesFromMdl
    • PsCreateSystemThread
    • PsTerminateSystemThread
    • IoAllocateMdl
    • IofCompleteRequest
    • IoCreateDevice
    • IoCreateSymbolicLink
    • IoDeleteDevice
    • IoDeleteSymbolicLink
    • IoFreeMdl
    • IoReleaseCancelSpinLock
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwClose
    • ZwOpenKey
    • ZwQueryValueKey
    • PsGetCurrentProcessId
    • ZwSetInformationThread
    • RtlLengthSid
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwSetSecurityObject
    • __C_specific_handler
    • SeExports
    • RtlGetVersion
    • RtlCompareMemory
    • RtlValidSid

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2019-06-10 08:45:52
    MD5173779a1a53b6ac06dcf045bc78eed62
    SHA1c46e469d45ecc08a5b13a6d9d9b7f9c5a9fae008
    SHA25626d67d479dafe6b33c980bd1eed0b6d749f43d05d001c5dcaaf5fcddb9b899fe
    Authentihash MD5b42afd5a5225094c7943185e769bc995
    Authentihash SHA122c5e127e7e7c567d8624607a6f8f5809deacb55
    Authentihash SHA256de6bf572d39e2611773e7a01f0388f84fb25da6cba2f1f8b9b36ffba467de6fa
    RichPEHeaderHash MD5ea1a25e78d69ef318ef4d2fbfd420541
    RichPEHeaderHash SHA11f795bc5eaecf5ee96f77ae703426b5f65e0d895
    RichPEHeaderHash SHA2561c10422043879162a1e9a246a3125f545a119afc8c25fd6822f48509ee2a02c0
    Company宏图无忧
    DescriptionWYJSQ TDI Hook Driver (WPP)
    Product无忧加速器
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 09450b8f73ea43e39d2cdd56049dbe40
    FieldValue
    ToBeSigned (TBS) MD5bcfecc67375f580ac6eadd789860b1f8
    ToBeSigned (TBS) SHA13fa9cf13a1816a6e358bb1ca12e050662bc2e178
    ToBeSigned (TBS) SHA256fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df
    SubjectC=CN, ST=, L=, O=, CN=
    ValidFrom2019-06-27 00:00:00
    ValidTo2020-06-30 12:00:00
    Signature03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber09450b8f73ea43e39d2cdd56049dbe40
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 02c4d1e58a4a680c568da3047e7e4d5f
    FieldValue
    ToBeSigned (TBS) MD5829995f702421dea833a24fb2c7f4442
    ToBeSigned (TBS) SHA11d7e838accd498c2e5ba9373af819ec097bb955c
    ToBeSigned (TBS) SHA25692914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1
    ValidFrom2011-02-11 12:00:00
    ValidTo2026-02-10 12:00:00
    Signature49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber02c4d1e58a4a680c568da3047e7e4d5f
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll
    • TDI.SYS

    Imported Functions

    Expand
    • IoCreateSymbolicLink
    • IoCreateDevice
    • IoDeleteSymbolicLink
    • IofCompleteRequest
    • ZwClose
    • ObfDereferenceObject
    • ObOpenObjectByPointer
    • PsLookupProcessByProcessId
    • MmGetSystemRoutineAddress
    • RtlInitUnicodeString
    • IoDetachDevice
    • IofCallDriver
    • IoFreeMdl
    • memcpy
    • MmBuildMdlForNonPagedPool
    • IoBuildDeviceIoControlRequest
    • IoAllocateMdl
    • RtlDowncaseUnicodeString
    • PsGetCurrentProcessId
    • KeWaitForSingleObject
    • KeInitializeEvent
    • KeInsertQueueDpc
    • IoReleaseCancelSpinLock
    • ObReferenceObjectByHandle
    • IoDeleteDevice
    • MmMapLockedPagesSpecifyCache
    • IoAllocateIrp
    • KeInitializeTimer
    • KeInitializeDpc
    • RtlAppendUnicodeToString
    • IoAttachDeviceToDeviceStack
    • IoGetDeviceObjectPointer
    • ObfReferenceObject
    • KeSetTimer
    • MmFreePagesFromMdl
    • MmUnmapLockedPages
    • MmAllocatePagesForMdl
    • ZwQueryValueKey
    • ZwOpenKey
    • ZwSetSecurityObject
    • RtlSetDaclSecurityDescriptor
    • RtlCreateSecurityDescriptor
    • RtlAddAccessAllowedAce
    • RtlCreateAcl
    • RtlLengthSid
    • SeExports
    • KeTickCount
    • KeBugCheckEx
    • _aullrem
    • ExFreePoolWithTag
    • memset
    • IoFreeIrp
    • ExAllocatePoolWithTag
    • RtlUnwind
    • KfAcquireSpinLock
    • KfReleaseSpinLock
    • TdiMapUserRequest

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2020-09-15 00:54:17
    MD515cfb6e9841d553926aace5114fa8475
    SHA116211fd7b3dd8fd09181a7f4ed20e629e374c00b
    SHA2566703400b490b35bcde6e41ce1640920251855e6d94171170ae7ea22cdd0938c0
    Authentihash MD56d4517e6348130fe55f11bfd630d857f
    Authentihash SHA160a632e4b838731aad553650d6bc8af3d3d80b26
    Authentihash SHA2568168304169a2453c0c3e0a285c2a07d3b3b83433e0342f6b33400c371af86221
    RichPEHeaderHash MD54c93d23c41f384b75bda01c7ace495d8
    RichPEHeaderHash SHA128695a10b02de9e1ce2d2b70c463f5d3bbaeaf4c
    RichPEHeaderHash SHA2564049be109d3e76b72f97f3faab4a4456933bce7ec4593342fd7046ca2bae226e
    CompanyWindows (R) Win 7 DDK provider
    DescriptionNetFilter SDK WFP Driver (WPP)
    ProductWindows (R) Win 7 DDK driver
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 0108cbaee60728f5bf06e45a56d6f170
    FieldValue
    ToBeSigned (TBS) MD54e8398340fdf2c302ef881776b4626e7
    ToBeSigned (TBS) SHA1483073cdc5b9b560c2d5aa80b62fa184ae4467ba
    ToBeSigned (TBS) SHA256b9d8daa31a25a3c525aa5cb844ced8da586540f20dc0a004209c598a56b95401
    Subject??=CN, ??=, ??=, ??=Private Organization, serialNumber=91420100MA49KFRB44, C=CN, ST=, L=, O=, CN=
    ValidFrom2020-10-26 00:00:00
    ValidTo2022-10-27 23:59:59
    Signature79197d1bcfcf1e9bad9b6e106ff984000ed506986e884b44056fe05b8ea34d36f5b368551ee2848e3a9f55caad769e641dfb27e2a7182ceaf33b7b7a96a0f0ee966cb67377c2ceebdb72e7672079721ebfe265f3f3e95aa080d0f53fbf70b810e6af342243e6d7af74a9c9e0cec31200ab074e500ef8f8d11541d3409ee0a42835e8a6ce2b19385a2738d00b8e31f874c41e5cea3e30bee081840a3c83ad3aba7aff0240caacc839c0bdab5448d3376f3d7360eb77ba366cb7e3364f638ba48b37e82f03baa20868717f6c58a0175dd5417d1670e97c8dc8b6b021e39f5ce087b63a6de6f46968d7ee37135d40b309b56c12e314b46cd74a51638196a2e02e1c
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber0108cbaee60728f5bf06e45a56d6f170
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 0dd0e3374ac95bdbfa6b434b2a48ec06
    FieldValue
    ToBeSigned (TBS) MD5f92649915476229b093c211c2b18e6c4
    ToBeSigned (TBS) SHA12d54c16a8f8b69ccdea48d0603c132f547a5cf75
    ToBeSigned (TBS) SHA2562cd702a7dec30aa441345672e8992ef9770ce4946f276d767b45b0ed627658fb
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert EV Code Signing CA
    ValidFrom2012-04-18 12:00:00
    ValidTo2027-04-18 12:00:00
    Signature9e5b963a2e1288acab016da49f75e40187a3a532d7bcbaa97ea3d61417f7c2136b7c738f2b6ae50f265968b08e259b6ceffa6c939208c14dcf459e9c46d61e74a19b14a3fa012f4ab101e1724048111368b9369d914bd7c2391210c1c4dcbb6214142a615d4f387c661fc61bffadbe4f7f945b7343000f4d73b751cf0ef677c05bcd348cd96313aa0e6111d6f28e27fcb47bb8b91120918678ea0ed428ff2ad52438e837b2ec96bb9fbc4a1650e15ebf517d23a032c7c1949e7ac9c026a2cc2587a0127e749f2d8db1c8e784beb9d1e9debb6a4e887371e12238cb2487e9737e51b2ff98eb4e7e2fe0ca0efab35ed1ba0542a8489f83f63fc4caa8df68a05061
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber0dd0e3374ac95bdbfa6b434b2a48ec06
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll
    • fwpkclnt.sys
    • NDIS.SYS

    Imported Functions

    Expand
    • memcpy
    • RtlValidSid
    • IoFreeMdl
    • RtlUnwind
    • KeBugCheckEx
    • RtlCompareMemory
    • KeTickCount
    • _allmul
    • _aulldiv
    • KeQuerySystemTime
    • ExUuidCreate
    • swprintf_s
    • KeInitializeEvent
    • PsCreateSystemThread
    • ZwSetInformationThread
    • ObReferenceObjectByHandle
    • RtlAppendUnicodeToString
    • IoCreateDevice
    • IoCreateSymbolicLink
    • PsTerminateSystemThread
    • MmGetSystemRoutineAddress
    • PsLookupProcessByProcessId
    • IoAllocateMdl
    • MmBuildMdlForNonPagedPool
    • IoReleaseCancelSpinLock
    • PsGetCurrentProcessId
    • IofCompleteRequest
    • IoDeleteSymbolicLink
    • IoDeleteDevice
    • KeWaitForSingleObject
    • ObfDereferenceObject
    • MmAllocatePagesForMdl
    • MmMapLockedPagesSpecifyCache
    • MmFreePagesFromMdl
    • MmUnmapLockedPages
    • KeSetEvent
    • ObOpenObjectByPointer
    • RtlLengthSid
    • SeExports
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • ZwSetSecurityObject
    • ZwQueryValueKey
    • ExDeleteNPagedLookasideList
    • ExInitializeNPagedLookasideList
    • InterlockedPushEntrySList
    • InterlockedPopEntrySList
    • _aullrem
    • ExFreePoolWithTag
    • memset
    • ExAllocatePoolWithTag
    • RtlInitUnicodeString
    • ZwOpenKey
    • ZwClose
    • KeReleaseInStackQueuedSpinLock
    • KeGetCurrentIrql
    • KeAcquireInStackQueuedSpinLock
    • FwpsStreamInjectAsync0
    • FwpmEngineOpen0
    • FwpmProviderAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmProviderContextDeleteByKey0
    • FwpsAcquireClassifyHandle0
    • FwpsQueryPacketInjectionState0
    • FwpsFlowAssociateContext0
    • FwpmSubLayerAdd0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmFreeMemory0
    • FwpmSubLayerEnum0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmCalloutAdd0
    • FwpmFilterAdd0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmTransactionCommit0
    • FwpmTransactionAbort0
    • FwpsCalloutRegister1
    • FwpsCalloutUnregisterByKey0
    • FwpsPendClassify0
    • FwpsInjectionHandleCreate0
    • FwpsCopyStreamDataToBuffer0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpsAllocateNetBufferAndNetBufferList0
    • FwpsInjectTransportSendAsync0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsInjectNetworkSendAsync0
    • FwpsInjectTransportReceiveAsync0
    • FwpsFreeCloneNetBufferList0
    • FwpsInjectionHandleDestroy0
    • FwpsFlowRemoveContext0
    • FwpsCloneStreamData0
    • FwpsCompleteClassify0
    • FwpsReleaseClassifyHandle0
    • FwpsDiscardClonedStreamData0
    • FwpsFreeNetBufferList0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • FwpmBfeStateUnsubscribeChanges0
    • NdisFreeGenericObject
    • NdisInitializeEvent
    • NdisFreeNetBufferListPool
    • NdisGetDataBuffer
    • NdisAdvanceNetBufferDataStart
    • NdisRetreatNetBufferDataStart
    • NdisAllocateNetBufferListPool
    • NdisAllocateGenericObject
    • NdisWaitEvent

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2020-09-15 00:54:19
    MD5b04685112a0a8f7689c8d827bfcfe158
    SHA1c7e40abaae9aeff135fe313fb0283381e8cced4d
    SHA256db1dbb09d437d3e8bed08c88ca43769b4fe8728f68b78ff6f9c8d2557e28d2b1
    Authentihash MD50d76526227d593a8967ed866b5991e10
    Authentihash SHA13ae56ab63230d6d9552360845b4a37b5801cc5ea
    Authentihash SHA256e9b433a33dc72eb2622947b41f01d04a48cd71beac775a88f3f1e4c838090ee8
    RichPEHeaderHash MD55f9eb581b0ce6f9d2b5f1f5a9771af50
    RichPEHeaderHash SHA1cb1828152e4668b5e033ee126a52df4f76700b2a
    RichPEHeaderHash SHA256e9bd3b71a475097efee5f9196d05a582abc2323affe47c2c9cf9bf933004e22f
    CompanyWindows (R) Win 7 DDK provider
    DescriptionNetFilter SDK WFP Driver (WPP)
    ProductWindows (R) Win 7 DDK driver
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 330000003a6ae333708fda7a7b00000000003a
    FieldValue
    ToBeSigned (TBS) MD56f5d716e7151f1c173396adb7213359e
    ToBeSigned (TBS) SHA1100610baae90027e9844a8e9c4d489fe122ecd9c
    ToBeSigned (TBS) SHA256677d532777cee24be88442efec75e9640e80ef57d8e1246396459a1a04be733f
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher
    ValidFrom2020-03-11 17:31:14
    ValidTo2021-03-05 17:31:14
    Signature7dfc7c353c4c04d9d06066e1ca8584637192eb15d1d6e7c5521b0d819d615fb56524985d30535b0573fb8e0d13173d51b27bd23b9a2052738891d67ed360766452b62c4566eb20c90f018229a8e951bf58df5a7d731c1e51217f471d470979f04e900920bfc8715122b331d82f68f73ebf3de36e09d18fbfed2f3c29190a41baafbca0025bf4e36310a04cb8e61c32fda677820aa693a7f5e69d3c3abdb495b12bb8b6d10f65d44fae945d9b0fcf695d4711fc9e1c0ddb1f569c13093e16c389f748d8fe60e8685f02357464564761db4cece391baa742f3ad3bcfa26e01975966ca41939c832bf1147bec870162ce042fd0cf10d048181ec573d317f2c5de21512f13b24de9bac9bb83fc2ceb4f6f766536fe38c03ede1f8b0a3b8828e8d914d73d0a17699ab20264a27a36e0f77c5144cf470bf44d2296290e345bd25c0bc6a08dd963ec39ce0e500599751c652dc20e9906c1ce76c1d86c09058ae8defb3d7b93b68a34ca83a981a30c2403723f7e5c664b1e951050002ad32e976db221c2d8c660047dc6acfe0da16d44c6372a5cd04b016a35193f841b903ba87e2d6e416a2c59469af9f16e249bb891f21ec22f2db0a84a48d7a9e43d2f7e3bdd016d600f57daf21829885ec035287ab332c32738f5e26c6d2502b2f044afb1e048c85c7c9baf76747de14ecdeca3c7481796a741672a047f89dafe2c12c01982a026c4
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber330000003a6ae333708fda7a7b00000000003a
    Version3
    Certificate 330000000d690d5d7893d076df00000000000d
    FieldValue
    ToBeSigned (TBS) MD583f69422963f11c3c340b81712eef319
    ToBeSigned (TBS) SHA10c5e5f24590b53bc291e28583acb78e5adc95601
    ToBeSigned (TBS) SHA256d8be9e4d9074088ef818bc6f6fb64955e90378b2754155126feebbbd969cf0ae
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2014
    ValidFrom2014-10-15 20:31:27
    ValidTo2029-10-15 20:41:27
    Signature96b5c33b31f27b6ba11f59dd742c3764b1bca093f9f33347e9f95df21d89f4579ee33f10a3595018053b142941b6a70e5b81a2ccbd8442c1c4bed184c2c4bd0c8c47bcbd8886fb5a0896ae2c2fdfbf9366a32b20ca848a6945273f732332936a23e9fffdd918edceffbd6b41738d579cf8b46d499805e6a335a9f07e6e86c06ba8086725afc0998cdba7064d4093188ba959e69914b912178144ac57c3ae8eae947bcb3b8edd7ab4715bba2bc3c7d085234b371277a54a2f7f1ab763b94459ed9230cce47c099212111f52f51e0291a4d7d7e58f8047ff189b7fd19c0671dcf376197790d52a0fbc6c12c4c50c2066f50e2f5093d8cafb7fe556ed09d8a753b1c72a6978dcf05fe74b20b6af63b5e1b15c804e9c7aa91d4df72846782106954d32dd6042e4b61ac4f24636de357302c1b5e55fb92b59457a9243d7c4e963dd368f76c728caa8441be8321a66cde5485c4a0a602b469206609698dcd933d721777f886dac4772daa2466eab64682bd24e98fb35cc7fec3f136d11e5db77edc1c37e1f6a4a14f8b4a721c671866770cdd819a35d1fa09b9a7cc55d4d728e74077fa74d00fcdd682412772a557527cda92c1d8e7c19ee692c9f7425338208db38cc7cc74f6c3a6bc237117872fe55596460333e2edfc42de72cd7fb0a82256fb8d70c84a5e1c4746e2a95329ea0fecdb4188fd33bad32b2b19ab86d0543fbff0d0f
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber330000000d690d5d7893d076df00000000000d
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • fwpkclnt.sys
    • NDIS.SYS

    Imported Functions

    Expand
    • KeBugCheckEx
    • ExUuidCreate
    • swprintf_s
    • RtlCreateSecurityDescriptor
    • RtlLengthSid
    • IoAllocateMdl
    • ObOpenObjectByPointer
    • IoReleaseCancelSpinLock
    • IoCreateDevice
    • MmFreePagesFromMdl
    • ObfDereferenceObject
    • PsGetCurrentProcessId
    • IoCreateSymbolicLink
    • SeExports
    • ZwSetSecurityObject
    • KeWaitForSingleObject
    • ObReferenceObjectByHandle
    • ZwSetInformationThread
    • IofCompleteRequest
    • PsTerminateSystemThread
    • ZwQueryValueKey
    • MmMapLockedPagesSpecifyCache
    • PsCreateSystemThread
    • RtlAddAccessAllowedAce
    • MmBuildMdlForNonPagedPool
    • MmAllocatePagesForMdl
    • KeInitializeEvent
    • RtlAppendUnicodeToString
    • MmGetSystemRoutineAddress
    • KeSetEvent
    • IoDeleteDevice
    • RtlSetDaclSecurityDescriptor
    • PsLookupProcessByProcessId
    • RtlCreateAcl
    • IoDeleteSymbolicLink
    • MmUnmapLockedPages
    • RtlCompareMemory
    • RtlValidSid
    • ExDeleteNPagedLookasideList
    • ExQueryDepthSList
    • IoFreeMdl
    • ExpInterlockedPopEntrySList
    • KeAcquireInStackQueuedSpinLock
    • ExpInterlockedPushEntrySList
    • KeReleaseInStackQueuedSpinLock
    • ExInitializeNPagedLookasideList
    • ExFreePoolWithTag
    • ExAllocatePoolWithTag
    • ZwOpenKey
    • ZwClose
    • RtlInitUnicodeString
    • __C_specific_handler
    • FwpsFlowAssociateContext0
    • FwpsCalloutUnregisterByKey0
    • FwpmSubLayerAdd0
    • FwpsQueryPacketInjectionState0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerEnum0
    • FwpmTransactionCommit0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmProviderContextDeleteByKey0
    • FwpmCalloutAdd0
    • FwpmProviderAdd0
    • FwpmTransactionAbort0
    • FwpmEngineOpen0
    • FwpsAcquireClassifyHandle0
    • FwpmFilterAdd0
    • FwpsPendClassify0
    • FwpsCalloutRegister1
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmFreeMemory0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsFreeCloneNetBufferList0
    • FwpsInjectionHandleDestroy0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsAllocateNetBufferAndNetBufferList0
    • FwpsInjectionHandleCreate0
    • FwpsInjectTransportReceiveAsync0
    • FwpsInjectNetworkSendAsync0
    • FwpsCopyStreamDataToBuffer0
    • FwpsInjectTransportSendAsync0
    • FwpsFlowRemoveContext0
    • FwpsCloneStreamData0
    • FwpsCompleteClassify0
    • FwpsStreamInjectAsync0
    • FwpsReleaseClassifyHandle0
    • FwpsDiscardClonedStreamData0
    • FwpsFreeNetBufferList0
    • FwpmBfeStateUnsubscribeChanges0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • NdisAllocateGenericObject
    • NdisWaitEvent
    • NdisAllocateNetBufferListPool
    • NdisInitializeEvent
    • NdisFreeGenericObject
    • NdisFreeNetBufferListPool
    • NdisGetDataBuffer
    • NdisRetreatNetBufferDataStart
    • NdisAdvanceNetBufferDataStart

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2020-09-15 00:54:42
    MD5e5df31054a60be8aa858a28a8fe0f73e
    SHA148559c488bc304d39f87855b2225f8c0f7d74b59
    SHA25681bcd8a3f8c17ac6dc4bad750ad3417914db10aa15485094eef0951a3f72bdbd
    Authentihash MD552cef25aecab8b66f05e29df206d6375
    Authentihash SHA14e5e719362cd48bb323803c1d00afde11d4b9d4c
    Authentihash SHA25644a0599defea351314663582dbc61069b3a095a4ddad571bb17dd0d8b21e7ff2
    RichPEHeaderHash MD5b873ce00fb531a917db2341eff66f88d
    RichPEHeaderHash SHA10f24abad7feabd2abb4b819dedc5ab9b9de3e33c
    RichPEHeaderHash SHA25654b267b1987fc423443455d94ce6d7b42dd9357bef9de2d67bea3bc6a83fb0cc
    CompanyWindows (R) Win 7 DDK provider
    DescriptionNetFilter SDK WFP Driver (WPP)
    ProductWindows (R) Win 7 DDK driver
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 330000003a6ae333708fda7a7b00000000003a
    FieldValue
    ToBeSigned (TBS) MD56f5d716e7151f1c173396adb7213359e
    ToBeSigned (TBS) SHA1100610baae90027e9844a8e9c4d489fe122ecd9c
    ToBeSigned (TBS) SHA256677d532777cee24be88442efec75e9640e80ef57d8e1246396459a1a04be733f
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher
    ValidFrom2020-03-11 17:31:14
    ValidTo2021-03-05 17:31:14
    Signature7dfc7c353c4c04d9d06066e1ca8584637192eb15d1d6e7c5521b0d819d615fb56524985d30535b0573fb8e0d13173d51b27bd23b9a2052738891d67ed360766452b62c4566eb20c90f018229a8e951bf58df5a7d731c1e51217f471d470979f04e900920bfc8715122b331d82f68f73ebf3de36e09d18fbfed2f3c29190a41baafbca0025bf4e36310a04cb8e61c32fda677820aa693a7f5e69d3c3abdb495b12bb8b6d10f65d44fae945d9b0fcf695d4711fc9e1c0ddb1f569c13093e16c389f748d8fe60e8685f02357464564761db4cece391baa742f3ad3bcfa26e01975966ca41939c832bf1147bec870162ce042fd0cf10d048181ec573d317f2c5de21512f13b24de9bac9bb83fc2ceb4f6f766536fe38c03ede1f8b0a3b8828e8d914d73d0a17699ab20264a27a36e0f77c5144cf470bf44d2296290e345bd25c0bc6a08dd963ec39ce0e500599751c652dc20e9906c1ce76c1d86c09058ae8defb3d7b93b68a34ca83a981a30c2403723f7e5c664b1e951050002ad32e976db221c2d8c660047dc6acfe0da16d44c6372a5cd04b016a35193f841b903ba87e2d6e416a2c59469af9f16e249bb891f21ec22f2db0a84a48d7a9e43d2f7e3bdd016d600f57daf21829885ec035287ab332c32738f5e26c6d2502b2f044afb1e048c85c7c9baf76747de14ecdeca3c7481796a741672a047f89dafe2c12c01982a026c4
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber330000003a6ae333708fda7a7b00000000003a
    Version3
    Certificate 330000000d690d5d7893d076df00000000000d
    FieldValue
    ToBeSigned (TBS) MD583f69422963f11c3c340b81712eef319
    ToBeSigned (TBS) SHA10c5e5f24590b53bc291e28583acb78e5adc95601
    ToBeSigned (TBS) SHA256d8be9e4d9074088ef818bc6f6fb64955e90378b2754155126feebbbd969cf0ae
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2014
    ValidFrom2014-10-15 20:31:27
    ValidTo2029-10-15 20:41:27
    Signature96b5c33b31f27b6ba11f59dd742c3764b1bca093f9f33347e9f95df21d89f4579ee33f10a3595018053b142941b6a70e5b81a2ccbd8442c1c4bed184c2c4bd0c8c47bcbd8886fb5a0896ae2c2fdfbf9366a32b20ca848a6945273f732332936a23e9fffdd918edceffbd6b41738d579cf8b46d499805e6a335a9f07e6e86c06ba8086725afc0998cdba7064d4093188ba959e69914b912178144ac57c3ae8eae947bcb3b8edd7ab4715bba2bc3c7d085234b371277a54a2f7f1ab763b94459ed9230cce47c099212111f52f51e0291a4d7d7e58f8047ff189b7fd19c0671dcf376197790d52a0fbc6c12c4c50c2066f50e2f5093d8cafb7fe556ed09d8a753b1c72a6978dcf05fe74b20b6af63b5e1b15c804e9c7aa91d4df72846782106954d32dd6042e4b61ac4f24636de357302c1b5e55fb92b59457a9243d7c4e963dd368f76c728caa8441be8321a66cde5485c4a0a602b469206609698dcd933d721777f886dac4772daa2466eab64682bd24e98fb35cc7fec3f136d11e5db77edc1c37e1f6a4a14f8b4a721c671866770cdd819a35d1fa09b9a7cc55d4d728e74077fa74d00fcdd682412772a557527cda92c1d8e7c19ee692c9f7425338208db38cc7cc74f6c3a6bc237117872fe55596460333e2edfc42de72cd7fb0a82256fb8d70c84a5e1c4746e2a95329ea0fecdb4188fd33bad32b2b19ab86d0543fbff0d0f
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber330000000d690d5d7893d076df00000000000d
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • NDIS.SYS
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • FwpmTransactionCommit0
    • FwpmTransactionAbort0
    • FwpmProviderAdd0
    • FwpmProviderContextDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmSubLayerEnum0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmCalloutAdd0
    • FwpmFilterAdd0
    • FwpsFlowAbort0
    • FwpsInjectionHandleCreate0
    • FwpsInjectionHandleDestroy0
    • FwpsAllocateNetBufferAndNetBufferList0
    • FwpsFreeNetBufferList0
    • FwpmTransactionBegin0
    • FwpsInjectNetworkSendAsync0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsInjectTransportSendAsync0
    • FwpsInjectTransportReceiveAsync0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsStreamInjectAsync0
    • FwpsCopyStreamDataToBuffer0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • FwpmBfeStateUnsubscribeChanges0
    • FwpsFlowRemoveContext0
    • FwpsCompleteClassify0
    • FwpsRedirectHandleDestroy0
    • FwpsCloneStreamData0
    • FwpsDiscardClonedStreamData0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpmFreeMemory0
    • FwpsRedirectHandleCreate0
    • FwpsQueryPacketInjectionState0
    • FwpsApplyModifiedLayerData0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsReleaseClassifyHandle0
    • FwpsFlowAssociateContext0
    • FwpsAcquireClassifyHandle0
    • FwpsCalloutUnregisterByKey0
    • FwpsCalloutRegister1
    • FwpsPendClassify0
    • FwpsFreeCloneNetBufferList0
    • NdisAllocateNetBufferListPool
    • NdisWaitEvent
    • NdisInitializeEvent
    • NdisFreeGenericObject
    • NdisAllocateGenericObject
    • NdisGetDataBuffer
    • NdisAdvanceNetBufferDataStart
    • NdisRetreatNetBufferDataStart
    • NdisFreeNetBufferListPool
    • memset
    • RtlInitUnicodeString
    • MmGetSystemRoutineAddress
    • RtlAppendUnicodeToString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeInitializeEvent
    • KeSetEvent
    • KeWaitForSingleObject
    • KeInitializeSpinLock
    • ExFreePoolWithTag
    • InterlockedPopEntrySList
    • InterlockedPushEntrySList
    • ExInitializeNPagedLookasideList
    • ExDeleteNPagedLookasideList
    • MmBuildMdlForNonPagedPool
    • MmMapLockedPagesSpecifyCache
    • MmUnmapLockedPages
    • MmAllocatePagesForMdl
    • MmFreePagesFromMdl
    • PsCreateSystemThread
    • PsTerminateSystemThread
    • IoAllocateMdl
    • IofCompleteRequest
    • IoCreateDevice
    • IoCreateSymbolicLink
    • IoDeleteDevice
    • IoDeleteSymbolicLink
    • IoFreeMdl
    • IoReleaseCancelSpinLock
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwClose
    • ZwOpenKey
    • ZwQueryValueKey
    • PsGetCurrentProcessId
    • ZwSetInformationThread
    • RtlLengthSid
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwSetSecurityObject
    • SeExports
    • RtlGetVersion
    • KeQuerySystemTime
    • _allmul
    • _aulldiv
    • _aullrem
    • RtlCompareMemory
    • RtlValidSid
    • RtlUnwind
    • memcpy
    • ExUuidCreate
    • ExAllocatePoolWithTag
    • swprintf_s
    • KeReleaseInStackQueuedSpinLock
    • KeGetCurrentIrql
    • KeAcquireInStackQueuedSpinLock

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2019-06-10 08:45:42
    MD5c3e397dc9fb61a75521548048458a018
    SHA1708c327256e1aea27572cdfc07ab44c22eb19aae
    SHA2567ff8fe4c220cf6416984b70a7e272006a018e5662da3cedc2a88efeb6411b4a4
    Authentihash MD5fd8b9266dc98e0af514babcbba122265
    Authentihash SHA1dc38cc55b84a1a7c0846fb5509b43b4ff97a9be6
    Authentihash SHA256fafa1bb36f0ac34b762a10e9f327dcab2152a6d0b16a19697362d49a31e7f566
    RichPEHeaderHash MD5a56ba6fc66a7556100c90b00913a984c
    RichPEHeaderHash SHA1b236fd12e7887836407fd8ff0acd7192685f3704
    RichPEHeaderHash SHA256464507424adf04e3a3c84ab69df0eb8a21f311a35cdf11ad898a50995fbfba19
    Company宏图无忧
    DescriptionWYJSQ WFP Driver (WPP)
    Product无忧加速器
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 09450b8f73ea43e39d2cdd56049dbe40
    FieldValue
    ToBeSigned (TBS) MD5bcfecc67375f580ac6eadd789860b1f8
    ToBeSigned (TBS) SHA13fa9cf13a1816a6e358bb1ca12e050662bc2e178
    ToBeSigned (TBS) SHA256fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df
    SubjectC=CN, ST=, L=, O=, CN=
    ValidFrom2019-06-27 00:00:00
    ValidTo2020-06-30 12:00:00
    Signature03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber09450b8f73ea43e39d2cdd56049dbe40
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 02c4d1e58a4a680c568da3047e7e4d5f
    FieldValue
    ToBeSigned (TBS) MD5829995f702421dea833a24fb2c7f4442
    ToBeSigned (TBS) SHA11d7e838accd498c2e5ba9373af819ec097bb955c
    ToBeSigned (TBS) SHA25692914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1
    ValidFrom2011-02-11 12:00:00
    ValidTo2026-02-10 12:00:00
    Signature49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber02c4d1e58a4a680c568da3047e7e4d5f
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • fwpkclnt.sys
    • NDIS.SYS

    Imported Functions

    Expand
    • KeBugCheckEx
    • ExUuidCreate
    • swprintf_s
    • RtlCreateSecurityDescriptor
    • RtlLengthSid
    • IoAllocateMdl
    • ObOpenObjectByPointer
    • IoReleaseCancelSpinLock
    • IoCreateDevice
    • MmFreePagesFromMdl
    • ObfDereferenceObject
    • PsGetCurrentProcessId
    • IoCreateSymbolicLink
    • SeExports
    • ZwSetSecurityObject
    • KeWaitForSingleObject
    • ObReferenceObjectByHandle
    • ZwSetInformationThread
    • IofCompleteRequest
    • PsTerminateSystemThread
    • ZwQueryValueKey
    • MmMapLockedPagesSpecifyCache
    • PsCreateSystemThread
    • RtlAddAccessAllowedAce
    • MmBuildMdlForNonPagedPool
    • MmAllocatePagesForMdl
    • KeInitializeEvent
    • RtlAppendUnicodeToString
    • MmGetSystemRoutineAddress
    • KeSetEvent
    • IoDeleteDevice
    • RtlSetDaclSecurityDescriptor
    • PsLookupProcessByProcessId
    • RtlCreateAcl
    • IoDeleteSymbolicLink
    • MmUnmapLockedPages
    • ExDeleteNPagedLookasideList
    • ExQueryDepthSList
    • IoFreeMdl
    • ExpInterlockedPopEntrySList
    • KeAcquireInStackQueuedSpinLock
    • ExpInterlockedPushEntrySList
    • KeReleaseInStackQueuedSpinLock
    • ExInitializeNPagedLookasideList
    • ExFreePoolWithTag
    • ExAllocatePoolWithTag
    • ZwOpenKey
    • ZwClose
    • RtlInitUnicodeString
    • __C_specific_handler
    • FwpsFlowAssociateContext0
    • FwpsCalloutUnregisterByKey0
    • FwpmSubLayerAdd0
    • FwpsQueryPacketInjectionState0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerEnum0
    • FwpmTransactionCommit0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmProviderContextDeleteByKey0
    • FwpmCalloutAdd0
    • FwpmProviderAdd0
    • FwpmTransactionAbort0
    • FwpmEngineOpen0
    • FwpsAcquireClassifyHandle0
    • FwpmFilterAdd0
    • FwpsPendClassify0
    • FwpsCalloutRegister1
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmFreeMemory0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsFreeCloneNetBufferList0
    • FwpsInjectionHandleDestroy0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsAllocateNetBufferAndNetBufferList0
    • FwpsInjectionHandleCreate0
    • FwpsInjectTransportReceiveAsync0
    • FwpsInjectNetworkSendAsync0
    • FwpsCopyStreamDataToBuffer0
    • FwpsInjectTransportSendAsync0
    • FwpsFlowRemoveContext0
    • FwpsCloneStreamData0
    • FwpsCompleteClassify0
    • FwpsStreamInjectAsync0
    • FwpsReleaseClassifyHandle0
    • FwpsDiscardClonedStreamData0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • FwpmBfeStateUnsubscribeChanges0
    • FwpsFreeNetBufferList0
    • NdisAllocateGenericObject
    • NdisWaitEvent
    • NdisAllocateNetBufferListPool
    • NdisInitializeEvent
    • NdisFreeGenericObject
    • NdisFreeNetBufferListPool
    • NdisGetDataBuffer
    • NdisRetreatNetBufferDataStart
    • NdisAdvanceNetBufferDataStart

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2020-09-15 00:54:41
    MD5305b05de211be69446444284923bd676
    SHA14d8a4115826eef6d9acd2487b141facf5b87a257
    SHA2561a0f57a4d7c8137baf24c65d542729547b876979273df7a245aaeea87280c090
    Authentihash MD53361957860d2b65c0368778ca088946f
    Authentihash SHA16a784d45517142c11d5cca3ff9956b2ed6eaf4c9
    Authentihash SHA256e94e8a87459db56837d1c58f9854794aa99f36566a9ded9b398be9d4d3a2c2af
    RichPEHeaderHash MD5c646eed94ec9e75c1a5498d3642cdab3
    RichPEHeaderHash SHA10d0761641e424cc895ba76723784427fcf297f4a
    RichPEHeaderHash SHA2567cecb42d3d4ae8649f3b4714fbab29c4cef8e24a48b0eea2537824fc40f4ea7f
    CompanyWindows (R) Win 7 DDK provider
    DescriptionNetFilter SDK WFP Driver (WPP)
    ProductWindows (R) Win 7 DDK driver
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 4b51e8986bf2670974fecc6dad020f19
    FieldValue
    ToBeSigned (TBS) MD50538926e1c7f1fcaee6540250d010840
    ToBeSigned (TBS) SHA159887d34eaaa74baf151589daef69b2b6f2d9b55
    ToBeSigned (TBS) SHA256b52255871658ceb663a52576f271ee86d661c2594fc3aa93bbf62ce8a8c77428
    SubjectC=IN, ST=Rajasthan, L=Jaipur, O=SYSTWEAK SOFTWARE PVT. LTD., CN=SYSTWEAK SOFTWARE PVT. LTD.
    ValidFrom2020-07-03 00:00:00
    ValidTo2021-09-01 23:59:59
    Signature658280479fe306aab0994dc8906bc888a766f0a7cdf8b6e0f6008bee7672c4e903d8433af6a9b719a6089420404c164022d367e638da20898cfc10d30970a527a88fbb47ad4c50c44c14028ee1618992c921ac6c2fd07222d6751dba49b2c55b118de67b36d8cd7aa3e217f3a9d23ed2ad9c089d396ae12ed4b3d0fa3cf699c874f21001dcd68d2d8e11ea0d80c3721c7a961ab416dbf6351b81ba036b22b25c739614aa9c724555082c0c61d8600bbf5067132ae87773a8eace86519881e9dd89651a6dde6ab0a36e328e38d243e71ffb5dcbc287c163189c254950c1758d7e765b6d51460d94b6c0b8d185b687d3b4b686f0e5615df352747a1b5c3b1a1072
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber4b51e8986bf2670974fecc6dad020f19
    Version3
    Certificate 3d78d7f9764960b2617df4f01eca862a
    FieldValue
    ToBeSigned (TBS) MD51f056ff7d5f874984dc605402b7cb042
    ToBeSigned (TBS) SHA1bdb348353a2203deb4b767914fa1bd7248dd728b
    ToBeSigned (TBS) SHA256a08e79c386083d875014c409c13d144e0a24386132980df11ff59737c8489eb1
    SubjectC=US, O=Symantec Corporation, OU=Symantec Trust Network, CN=Symantec Class 3 SHA256 Code Signing CA
    ValidFrom2013-12-10 00:00:00
    ValidTo2023-12-09 23:59:59
    Signature13851a1e69a937f7a0bda4af7e1d6153fe9d8c5e0ca6751e781723ddfdec1a035539fb7195c7655aa78e30d2445a61db706fda2105c22e73ba49f1d193fe5dc9cd5e03e0899e3f741ed7f7388ba9d6cfbb352f3358a89256d1c84d3b82e6798416fc28b0b147f31da23eee87d9a67fa456a53fad842e29de7cbca8aaa33d0401eaba93a20e502229174c87e43a115fd6a425899b056b2fb4c9014c277b0bac190522a060153fdac9fb4d4c8ffb726777fd2794c7ba350e8849fe8dfd28af4a12bd0db39705de440c15fa362b03dcc15001f1a1115d14e5e2bd274b54be2b845e0fa6c374050aef97c38922b11f77f3bdcd43d4f14ca93fb58b84af64f2d01421
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber3d78d7f9764960b2617df4f01eca862a
    Version3
    Certificate 611993e400000000001c
    FieldValue
    ToBeSigned (TBS) MD578a717e082dcc1cda3458d917e677d14
    ToBeSigned (TBS) SHA14a872e0e51f9b304469cd1dedb496ee9b8b983a4
    ToBeSigned (TBS) SHA256317fa1d234ebc49040ebc5e8746f8997471496051b185a91bdd9dfbb23fab5f8
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. , For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority , G5
    ValidFrom2011-02-22 19:25:17
    ValidTo2021-02-22 19:35:17
    Signature812a82168c34672be503eb347b8ca2a3508af45586f11e8c8eae7dee0319ce72951848ad6211fd20fd3f4706015ae2e06f8c152c4e3c6a506c0b36a3cf7a0d9c42bc5cf819d560e369e6e22341678c6883762b8f93a32ab57fbe59fba9c9b2268fcaa2f3821b983e919527978661ee5b5d076bcd86a8e26580a8e215e2b2be23056aba0cf347934daca48c077939c061123a050d89a3ec9f578984fbecca7c47661491d8b60f195de6b84aacbc47c8714396e63220a5dc7786fd3ce38b71db7b9b03fcb71d3264eb1652a043a3fa2ead59924e7cc7f233424838513a7c38c71b242228401e1a461f17db18f7f027356cb863d9cdb9645d2ba55eefc629b4f2c7f821cc04ba57fd01b6abc667f9e7d3997ff4f522fa72f5fdff3a1c423aa1f98018a5ee8d1cd4669e4501feaaeefffb178f30f7f1cd29c59decb5d549003d85b8cbbb933a276a49c030ae66c9f723283276f9a48356c848ce5a96aaa0cc0cc47fb48e97af6de35427c39f86c0d6e473089705dbd054625e0348c2d59f7fa7668cd09db04fd4d3985f4b7ac97fb22952d01280c70f54b61e67cdc6a06c110384d34875e72afeb03b6e0a3aa66b769905a3f177686133144706fc537f52bd92145c4a246a678caf8d90aad0f679211b93267cc3ce1ebd883892ae45c6196a4950b305f8ae59378a6a250394b1598150e8ba8380b72335f476b9671d5918ad208d94
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber611993e400000000001c
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • NDIS.SYS
    • ntoskrnl.exe

    Imported Functions

    Expand
    • FwpmFreeMemory0
    • FwpmEngineOpen0
    • FwpmEngineClose0
    • FwpmTransactionBegin0
    • FwpmTransactionCommit0
    • FwpmTransactionAbort0
    • FwpmProviderAdd0
    • FwpmProviderContextDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmSubLayerEnum0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmCalloutAdd0
    • FwpmFilterAdd0
    • FwpsFlowAbort0
    • FwpsInjectionHandleCreate0
    • FwpsInjectionHandleDestroy0
    • FwpsRedirectHandleCreate0
    • FwpsFreeNetBufferList0
    • FwpsFreeCloneNetBufferList0
    • FwpsInjectNetworkSendAsync0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsInjectTransportSendAsync0
    • FwpsInjectTransportReceiveAsync0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsStreamInjectAsync0
    • FwpsCopyStreamDataToBuffer0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • FwpmBfeStateUnsubscribeChanges0
    • FwpsFlowRemoveContext0
    • FwpsCompleteClassify0
    • FwpsRedirectHandleDestroy0
    • FwpsCloneStreamData0
    • FwpsDiscardClonedStreamData0
    • FwpsQueryPacketInjectionState0
    • FwpsApplyModifiedLayerData0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsReleaseClassifyHandle0
    • FwpsAcquireClassifyHandle0
    • FwpsFlowAssociateContext0
    • FwpsCalloutUnregisterByKey0
    • FwpsCalloutRegister1
    • FwpsPendClassify0
    • FwpsAllocateNetBufferAndNetBufferList0
    • NdisFreeNetBufferListPool
    • NdisAllocateNetBufferListPool
    • NdisWaitEvent
    • NdisInitializeEvent
    • NdisFreeGenericObject
    • NdisAllocateGenericObject
    • NdisGetDataBuffer
    • NdisAdvanceNetBufferDataStart
    • NdisRetreatNetBufferDataStart
    • KeAcquireInStackQueuedSpinLock
    • KeReleaseInStackQueuedSpinLock
    • ExAllocatePoolWithTag
    • ExUuidCreate
    • swprintf_s
    • RtlInitUnicodeString
    • MmGetSystemRoutineAddress
    • RtlAppendUnicodeToString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeInitializeEvent
    • KeSetEvent
    • KeWaitForSingleObject
    • KeInitializeSpinLock
    • ExFreePoolWithTag
    • ExQueryDepthSList
    • ExpInterlockedPopEntrySList
    • ExpInterlockedPushEntrySList
    • ExInitializeNPagedLookasideList
    • ExDeleteNPagedLookasideList
    • MmBuildMdlForNonPagedPool
    • MmMapLockedPagesSpecifyCache
    • MmUnmapLockedPages
    • MmAllocatePagesForMdl
    • MmFreePagesFromMdl
    • PsCreateSystemThread
    • PsTerminateSystemThread
    • IoAllocateMdl
    • IofCompleteRequest
    • IoCreateDevice
    • IoCreateSymbolicLink
    • IoDeleteDevice
    • IoDeleteSymbolicLink
    • IoFreeMdl
    • IoReleaseCancelSpinLock
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwClose
    • ZwOpenKey
    • ZwQueryValueKey
    • PsGetCurrentProcessId
    • ZwSetInformationThread
    • RtlLengthSid
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwSetSecurityObject
    • __C_specific_handler
    • SeExports
    • RtlGetVersion
    • RtlCompareMemory
    • RtlValidSid

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2020-09-15 00:54:42
    MD53e5c04eced0e89aa8bfc279323c3544e
    SHA149f47fcb67f510b2d2ea891e1b1a50a95e0702ad
    SHA25662b14bb308c99132d90646e85bc7d6eb593f38e225c8232f69f24b74a019c176
    Authentihash MD552cef25aecab8b66f05e29df206d6375
    Authentihash SHA14e5e719362cd48bb323803c1d00afde11d4b9d4c
    Authentihash SHA25644a0599defea351314663582dbc61069b3a095a4ddad571bb17dd0d8b21e7ff2
    RichPEHeaderHash MD5b873ce00fb531a917db2341eff66f88d
    RichPEHeaderHash SHA10f24abad7feabd2abb4b819dedc5ab9b9de3e33c
    RichPEHeaderHash SHA25654b267b1987fc423443455d94ce6d7b42dd9357bef9de2d67bea3bc6a83fb0cc
    CompanyWindows (R) Win 7 DDK provider
    DescriptionNetFilter SDK WFP Driver (WPP)
    ProductWindows (R) Win 7 DDK driver
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 4b51e8986bf2670974fecc6dad020f19
    FieldValue
    ToBeSigned (TBS) MD50538926e1c7f1fcaee6540250d010840
    ToBeSigned (TBS) SHA159887d34eaaa74baf151589daef69b2b6f2d9b55
    ToBeSigned (TBS) SHA256b52255871658ceb663a52576f271ee86d661c2594fc3aa93bbf62ce8a8c77428
    SubjectC=IN, ST=Rajasthan, L=Jaipur, O=SYSTWEAK SOFTWARE PVT. LTD., CN=SYSTWEAK SOFTWARE PVT. LTD.
    ValidFrom2020-07-03 00:00:00
    ValidTo2021-09-01 23:59:59
    Signature658280479fe306aab0994dc8906bc888a766f0a7cdf8b6e0f6008bee7672c4e903d8433af6a9b719a6089420404c164022d367e638da20898cfc10d30970a527a88fbb47ad4c50c44c14028ee1618992c921ac6c2fd07222d6751dba49b2c55b118de67b36d8cd7aa3e217f3a9d23ed2ad9c089d396ae12ed4b3d0fa3cf699c874f21001dcd68d2d8e11ea0d80c3721c7a961ab416dbf6351b81ba036b22b25c739614aa9c724555082c0c61d8600bbf5067132ae87773a8eace86519881e9dd89651a6dde6ab0a36e328e38d243e71ffb5dcbc287c163189c254950c1758d7e765b6d51460d94b6c0b8d185b687d3b4b686f0e5615df352747a1b5c3b1a1072
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber4b51e8986bf2670974fecc6dad020f19
    Version3
    Certificate 3d78d7f9764960b2617df4f01eca862a
    FieldValue
    ToBeSigned (TBS) MD51f056ff7d5f874984dc605402b7cb042
    ToBeSigned (TBS) SHA1bdb348353a2203deb4b767914fa1bd7248dd728b
    ToBeSigned (TBS) SHA256a08e79c386083d875014c409c13d144e0a24386132980df11ff59737c8489eb1
    SubjectC=US, O=Symantec Corporation, OU=Symantec Trust Network, CN=Symantec Class 3 SHA256 Code Signing CA
    ValidFrom2013-12-10 00:00:00
    ValidTo2023-12-09 23:59:59
    Signature13851a1e69a937f7a0bda4af7e1d6153fe9d8c5e0ca6751e781723ddfdec1a035539fb7195c7655aa78e30d2445a61db706fda2105c22e73ba49f1d193fe5dc9cd5e03e0899e3f741ed7f7388ba9d6cfbb352f3358a89256d1c84d3b82e6798416fc28b0b147f31da23eee87d9a67fa456a53fad842e29de7cbca8aaa33d0401eaba93a20e502229174c87e43a115fd6a425899b056b2fb4c9014c277b0bac190522a060153fdac9fb4d4c8ffb726777fd2794c7ba350e8849fe8dfd28af4a12bd0db39705de440c15fa362b03dcc15001f1a1115d14e5e2bd274b54be2b845e0fa6c374050aef97c38922b11f77f3bdcd43d4f14ca93fb58b84af64f2d01421
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber3d78d7f9764960b2617df4f01eca862a
    Version3
    Certificate 611993e400000000001c
    FieldValue
    ToBeSigned (TBS) MD578a717e082dcc1cda3458d917e677d14
    ToBeSigned (TBS) SHA14a872e0e51f9b304469cd1dedb496ee9b8b983a4
    ToBeSigned (TBS) SHA256317fa1d234ebc49040ebc5e8746f8997471496051b185a91bdd9dfbb23fab5f8
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. , For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority , G5
    ValidFrom2011-02-22 19:25:17
    ValidTo2021-02-22 19:35:17
    Signature812a82168c34672be503eb347b8ca2a3508af45586f11e8c8eae7dee0319ce72951848ad6211fd20fd3f4706015ae2e06f8c152c4e3c6a506c0b36a3cf7a0d9c42bc5cf819d560e369e6e22341678c6883762b8f93a32ab57fbe59fba9c9b2268fcaa2f3821b983e919527978661ee5b5d076bcd86a8e26580a8e215e2b2be23056aba0cf347934daca48c077939c061123a050d89a3ec9f578984fbecca7c47661491d8b60f195de6b84aacbc47c8714396e63220a5dc7786fd3ce38b71db7b9b03fcb71d3264eb1652a043a3fa2ead59924e7cc7f233424838513a7c38c71b242228401e1a461f17db18f7f027356cb863d9cdb9645d2ba55eefc629b4f2c7f821cc04ba57fd01b6abc667f9e7d3997ff4f522fa72f5fdff3a1c423aa1f98018a5ee8d1cd4669e4501feaaeefffb178f30f7f1cd29c59decb5d549003d85b8cbbb933a276a49c030ae66c9f723283276f9a48356c848ce5a96aaa0cc0cc47fb48e97af6de35427c39f86c0d6e473089705dbd054625e0348c2d59f7fa7668cd09db04fd4d3985f4b7ac97fb22952d01280c70f54b61e67cdc6a06c110384d34875e72afeb03b6e0a3aa66b769905a3f177686133144706fc537f52bd92145c4a246a678caf8d90aad0f679211b93267cc3ce1ebd883892ae45c6196a4950b305f8ae59378a6a250394b1598150e8ba8380b72335f476b9671d5918ad208d94
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber611993e400000000001c
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • NDIS.SYS
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • FwpmTransactionCommit0
    • FwpmTransactionAbort0
    • FwpmProviderAdd0
    • FwpmProviderContextDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmSubLayerEnum0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmCalloutAdd0
    • FwpmFilterAdd0
    • FwpsFlowAbort0
    • FwpsInjectionHandleCreate0
    • FwpsInjectionHandleDestroy0
    • FwpsAllocateNetBufferAndNetBufferList0
    • FwpsFreeNetBufferList0
    • FwpmTransactionBegin0
    • FwpsInjectNetworkSendAsync0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsInjectTransportSendAsync0
    • FwpsInjectTransportReceiveAsync0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsStreamInjectAsync0
    • FwpsCopyStreamDataToBuffer0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • FwpmBfeStateUnsubscribeChanges0
    • FwpsFlowRemoveContext0
    • FwpsCompleteClassify0
    • FwpsRedirectHandleDestroy0
    • FwpsCloneStreamData0
    • FwpsDiscardClonedStreamData0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpmFreeMemory0
    • FwpsRedirectHandleCreate0
    • FwpsQueryPacketInjectionState0
    • FwpsApplyModifiedLayerData0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsReleaseClassifyHandle0
    • FwpsFlowAssociateContext0
    • FwpsAcquireClassifyHandle0
    • FwpsCalloutUnregisterByKey0
    • FwpsCalloutRegister1
    • FwpsPendClassify0
    • FwpsFreeCloneNetBufferList0
    • NdisAllocateNetBufferListPool
    • NdisWaitEvent
    • NdisInitializeEvent
    • NdisFreeGenericObject
    • NdisAllocateGenericObject
    • NdisGetDataBuffer
    • NdisAdvanceNetBufferDataStart
    • NdisRetreatNetBufferDataStart
    • NdisFreeNetBufferListPool
    • memset
    • RtlInitUnicodeString
    • MmGetSystemRoutineAddress
    • RtlAppendUnicodeToString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeInitializeEvent
    • KeSetEvent
    • KeWaitForSingleObject
    • KeInitializeSpinLock
    • ExFreePoolWithTag
    • InterlockedPopEntrySList
    • InterlockedPushEntrySList
    • ExInitializeNPagedLookasideList
    • ExDeleteNPagedLookasideList
    • MmBuildMdlForNonPagedPool
    • MmMapLockedPagesSpecifyCache
    • MmUnmapLockedPages
    • MmAllocatePagesForMdl
    • MmFreePagesFromMdl
    • PsCreateSystemThread
    • PsTerminateSystemThread
    • IoAllocateMdl
    • IofCompleteRequest
    • IoCreateDevice
    • IoCreateSymbolicLink
    • IoDeleteDevice
    • IoDeleteSymbolicLink
    • IoFreeMdl
    • IoReleaseCancelSpinLock
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwClose
    • ZwOpenKey
    • ZwQueryValueKey
    • PsGetCurrentProcessId
    • ZwSetInformationThread
    • RtlLengthSid
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwSetSecurityObject
    • SeExports
    • RtlGetVersion
    • KeQuerySystemTime
    • _allmul
    • _aulldiv
    • _aullrem
    • RtlCompareMemory
    • RtlValidSid
    • RtlUnwind
    • memcpy
    • ExUuidCreate
    • ExAllocatePoolWithTag
    • swprintf_s
    • KeReleaseInStackQueuedSpinLock
    • KeGetCurrentIrql
    • KeAcquireInStackQueuedSpinLock

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2019-06-10 08:45:42
    MD548357f3a359fa9c18f370f177c70298e
    SHA131ba5cc32a59e1915031b1363b7699116dfb1230
    SHA2561cd75de5f54b799b60789696587b56a4a793cf60775b81f236f0e65189d863af
    Authentihash MD5fd8b9266dc98e0af514babcbba122265
    Authentihash SHA1dc38cc55b84a1a7c0846fb5509b43b4ff97a9be6
    Authentihash SHA256fafa1bb36f0ac34b762a10e9f327dcab2152a6d0b16a19697362d49a31e7f566
    RichPEHeaderHash MD5a56ba6fc66a7556100c90b00913a984c
    RichPEHeaderHash SHA1b236fd12e7887836407fd8ff0acd7192685f3704
    RichPEHeaderHash SHA256464507424adf04e3a3c84ab69df0eb8a21f311a35cdf11ad898a50995fbfba19
    Company宏图无忧
    DescriptionWYJSQ WFP Driver (WPP)
    Product无忧加速器
    OriginalFilenamenetfilter2.sys

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 09450b8f73ea43e39d2cdd56049dbe40
    FieldValue
    ToBeSigned (TBS) MD5bcfecc67375f580ac6eadd789860b1f8
    ToBeSigned (TBS) SHA13fa9cf13a1816a6e358bb1ca12e050662bc2e178
    ToBeSigned (TBS) SHA256fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df
    SubjectC=CN, ST=, L=, O=, CN=
    ValidFrom2019-06-27 00:00:00
    ValidTo2020-06-30 12:00:00
    Signature03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber09450b8f73ea43e39d2cdd56049dbe40
    Version3
    Certificate 03019a023aff58b16bd6d5eae617f066
    FieldValue
    ToBeSigned (TBS) MD5a752afee44f017e8d74e3f3eb7914ae3
    ToBeSigned (TBS) SHA18eca80a6b80e9c69dcef7745748524afb8019e2d
    ToBeSigned (TBS) SHA25682560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1
    SubjectC=US, O=DigiCert, CN=DigiCert Timestamp Responder
    ValidFrom2014-10-22 00:00:00
    ValidTo2024-10-22 00:00:00
    Signature9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03019a023aff58b16bd6d5eae617f066
    Version3
    Certificate 02c4d1e58a4a680c568da3047e7e4d5f
    FieldValue
    ToBeSigned (TBS) MD5829995f702421dea833a24fb2c7f4442
    ToBeSigned (TBS) SHA11d7e838accd498c2e5ba9373af819ec097bb955c
    ToBeSigned (TBS) SHA25692914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1
    ValidFrom2011-02-11 12:00:00
    ValidTo2026-02-10 12:00:00
    Signature49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber02c4d1e58a4a680c568da3047e7e4d5f
    Version3
    Certificate 06fdf9039603adea000aeb3f27bbba1b
    FieldValue
    ToBeSigned (TBS) MD54e5ad189638cf52ba9cd881d4d44668c
    ToBeSigned (TBS) SHA1cdc115e98d798b33904c820d63cc1e1afc19251d
    ToBeSigned (TBS) SHA25637560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1
    ValidFrom2006-11-10 00:00:00
    ValidTo2021-11-10 00:00:00
    Signature46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber06fdf9039603adea000aeb3f27bbba1b
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • fwpkclnt.sys
    • NDIS.SYS

    Imported Functions

    Expand
    • KeBugCheckEx
    • ExUuidCreate
    • swprintf_s
    • RtlCreateSecurityDescriptor
    • RtlLengthSid
    • IoAllocateMdl
    • ObOpenObjectByPointer
    • IoReleaseCancelSpinLock
    • IoCreateDevice
    • MmFreePagesFromMdl
    • ObfDereferenceObject
    • PsGetCurrentProcessId
    • IoCreateSymbolicLink
    • SeExports
    • ZwSetSecurityObject
    • KeWaitForSingleObject
    • ObReferenceObjectByHandle
    • ZwSetInformationThread
    • IofCompleteRequest
    • PsTerminateSystemThread
    • ZwQueryValueKey
    • MmMapLockedPagesSpecifyCache
    • PsCreateSystemThread
    • RtlAddAccessAllowedAce
    • MmBuildMdlForNonPagedPool
    • MmAllocatePagesForMdl
    • KeInitializeEvent
    • RtlAppendUnicodeToString
    • MmGetSystemRoutineAddress
    • KeSetEvent
    • IoDeleteDevice
    • RtlSetDaclSecurityDescriptor
    • PsLookupProcessByProcessId
    • RtlCreateAcl
    • IoDeleteSymbolicLink
    • MmUnmapLockedPages
    • ExDeleteNPagedLookasideList
    • ExQueryDepthSList
    • IoFreeMdl
    • ExpInterlockedPopEntrySList
    • KeAcquireInStackQueuedSpinLock
    • ExpInterlockedPushEntrySList
    • KeReleaseInStackQueuedSpinLock
    • ExInitializeNPagedLookasideList
    • ExFreePoolWithTag
    • ExAllocatePoolWithTag
    • ZwOpenKey
    • ZwClose
    • RtlInitUnicodeString
    • __C_specific_handler
    • FwpsFlowAssociateContext0
    • FwpsCalloutUnregisterByKey0
    • FwpmSubLayerAdd0
    • FwpsQueryPacketInjectionState0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerEnum0
    • FwpmTransactionCommit0
    • FwpmSubLayerCreateEnumHandle0
    • FwpmSubLayerDestroyEnumHandle0
    • FwpmProviderContextDeleteByKey0
    • FwpmCalloutAdd0
    • FwpmProviderAdd0
    • FwpmTransactionAbort0
    • FwpmEngineOpen0
    • FwpsAcquireClassifyHandle0
    • FwpmFilterAdd0
    • FwpsPendClassify0
    • FwpsCalloutRegister1
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmFreeMemory0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpsInjectNetworkReceiveAsync0
    • FwpsFreeCloneNetBufferList0
    • FwpsInjectionHandleDestroy0
    • FwpsConstructIpHeaderForTransportPacket0
    • FwpsAllocateNetBufferAndNetBufferList0
    • FwpsInjectionHandleCreate0
    • FwpsInjectTransportReceiveAsync0
    • FwpsInjectNetworkSendAsync0
    • FwpsCopyStreamDataToBuffer0
    • FwpsInjectTransportSendAsync0
    • FwpsFlowRemoveContext0
    • FwpsCloneStreamData0
    • FwpsCompleteClassify0
    • FwpsStreamInjectAsync0
    • FwpsReleaseClassifyHandle0
    • FwpsDiscardClonedStreamData0
    • FwpmBfeStateGet0
    • FwpmBfeStateSubscribeChanges0
    • FwpmBfeStateUnsubscribeChanges0
    • FwpsFreeNetBufferList0
    • NdisAllocateGenericObject
    • NdisWaitEvent
    • NdisAllocateNetBufferListPool
    • NdisInitializeEvent
    • NdisFreeGenericObject
    • NdisFreeNetBufferListPool
    • NdisGetDataBuffer
    • NdisRetreatNetBufferDataStart
    • NdisAdvanceNetBufferDataStart

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Signature": "03dde89129103227d1e3b60f8112561b8b40ba165d1c9d6867aa730429a5534bb8fd6f9883704c5d2ddc938bbb8477a37ea3e01ecc696079a283e4d2534ca96b5049034c454324abf188ab6536ba0ee6e6f1f194a23363d9198eb829cf68834cd952074413bd9711e39037d0ecdba6ec2c7e2c7b46946c4ebea4ee1b84b7cb6582826da8eeafc5d1e9daf8f777480a7507017a6c485b25d94df9546c4ad4ebba85d79ce89422571b2e03557ba2b0396c4bacb5262e51cde8fe9c46d1f0e5e414757f53f5aded921c117f8c7bcf8caa4acc00b120c7a0a48ea84bd618e65c867d74367ab9f3285929c4f98e587f3620bb066906ffe450a911ded794c508f656a7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=, L=, O=, CN=",
          "TBS": {
            "MD5": "bcfecc67375f580ac6eadd789860b1f8",
            "SHA1": "3fa9cf13a1816a6e358bb1ca12e050662bc2e178",
            "SHA256": "fbb627aabbe2b2dbfdddfbad14392049b0d76f8d9679f3d550333b84b20320df",
            "SHA384": "d496c3920c3ab14a3c79e9bd41351912f045ea3b42ba9ec0cb0b1f778d1178174a831fe89848a8226957f2b6f079f01d"
          },
          "ValidFrom": "2019-06-27 00:00:00",
          "ValidTo": "2020-06-30 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03019a023aff58b16bd6d5eae617f066",
          "Signature": "9d257e1b334db226815c9b86ce23200f8087e588ffffb1d46a2c31ed3a17197117cda91bbc5a1639009de36c84e45a40fbde06018c37fa9bb19d247efe20a457ad5bb79ab06026ea6957215d342f1f71b0839419056b359010a07b97c7f63fe7e21141a6bd62d9f0273d381d286f3a5209f0ec7062d3624bb0e073a692c0d38e31d82fe36d171306eee403b614abf38f43a7719d21dd14ca155d9241daf90f81d199740d26c40e7f1bb5f5a0f1c677062815e9d893e55516f0bb0aab1cdb5c482766c8a38b0a1ce595daaec42e59a061dddaf36da261e98a0b6dec1218bdf755544003922b6bc251c20a48afb0d46ee0f4140a3a1be38f3dcaaf6a8d7bdcd844",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert, CN=DigiCert Timestamp Responder",
          "TBS": {
            "MD5": "a752afee44f017e8d74e3f3eb7914ae3",
            "SHA1": "8eca80a6b80e9c69dcef7745748524afb8019e2d",
            "SHA256": "82560fa7efec30b5ff82af643e6f3bf3d46868bbd5e7d76f93db185e9e3553a1",
            "SHA384": "e8b11408c88f877ade4ca51114a175fb5dfd2d18d2a66be547c1c9e080fa8f592c7870e30dfab1c04d234993dd0907f3"
          },
          "ValidFrom": "2014-10-22 00:00:00",
          "ValidTo": "2024-10-22 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "06fdf9039603adea000aeb3f27bbba1b",
          "Signature": "46503ec9b72824a7381db65b29af52cf52e93147ab565c7bd50d0b41b3efec751f7438f2b25c61a29c95c350e482b923d1ba3a8672ad3878ac755d1717347247859456d1ebbb368477cc24a5f3041955a9e7e3e7ab62cdfb8b2d90c2c0d2b594bd5e4fb105d20e3d1aa9145ba6863162a8a833e49b39a7c4f5ce1d7876942573e42aabcf9c764bed5fc24b16e44b704c00891efcc579bc4c1257fe5fe11ebc025da8fefb07384f0dc65d91b90f6745cdd683ede7920d8db1698c4ffb59e0230fd2aaae007cee9c420ecf91d727b716ee0fc3bd7c0aa0ee2c08558522b8eb181a4dfc2a21ad49318347957771dcb11b4b4b1c109c7714c19d4f2f5a9508291026",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID CA,1",
          "TBS": {
            "MD5": "4e5ad189638cf52ba9cd881d4d44668c",
            "SHA1": "cdc115e98d798b33904c820d63cc1e1afc19251d",
            "SHA256": "37560fb9d548ab62cc3ed4669a4ab74828b5a108e67e829937ffb2d10a5f78dd",
            "SHA384": "173bfb77183785621ef15f43ea807338cea6a02e8183317d9ef050c7237adda3fa2a5bdcd5a4c96da9f2c55900675b9f"
          },
          "ValidFrom": "2006-11-10 00:00:00",
          "ValidTo": "2021-11-10 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "09450b8f73ea43e39d2cdd56049dbe40",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    source

    last_updated: 2024-04-09