7edb5602-239f-460a-89d6-363ff1059765

viragt64.sys :inline :inline

Description

viragt64.sys is a vulnerable driver and more information will be added as found.

  • UUID: 7edb5602-239f-460a-89d6-363ff1059765
  • Created: 2023-05-06
  • Author: Nasreddine Bencherchali
  • Acknowledgement: |

DownloadBlock

This download link contains the vulnerable driver!

Commands

sc.exe create viragt64.sys binPath=C:\windows\temp\viragt64.sys type=kernel && sc.exe start viragt64.sys
Use CasePrivilegesOperating System
Elevate privilegeskernelWindows 10

Detections

YARA 🏹

Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed driver files

Sigma 🛡️

Expand

Names

detects loading using name only

Hashes

detects loading using hashes only

Sysmon 🔎

Expand

Block

on hashes

Alert

on hashes

Resources


  • Internal Research

  • Known Vulnerable Samples

    PropertyValue
    Filenameviragt64.sys
    Creation Timestamp2012-08-23 01:57:10
    MD5779af226b7b72ff9d78ce1f03d4a3389
    SHA19eef72e0c4d5055f6ae5fe49f7f812de29afbf37
    SHA25618deed37f60b6aa8634dda2565a0485452487d7bce88afb49301a7352db4e506
    Authentihash MD5835b8a268127c12be0ebcdd13eae3f16
    Authentihash SHA140082d350533c99578bdabfcaf03afe52c83d4a8
    Authentihash SHA2565f353fc46843155b6b63e75994f5328b9d4344654d5759a5145cd6e64babe3de
    RichPEHeaderHash MD55c2da98d3c7d93dc28810b2002ce0d6e
    RichPEHeaderHash SHA17f456a9479c32703788bae3343a1033564eaea02
    RichPEHeaderHash SHA256c02480322b0c662ee9626946cdcb09d460738355c470505d294deb2a34c6b62b
    CompanyTG Soft S.a.s.
    DescriptionVirIT Agent System
    ProductVirIT Agent System
    OriginalFilenameviragt64.sys

    Download

    Certificates

    Expand
    Certificate 79a2a585f9d1154213d9b83ef6b68ded
    FieldValue
    ToBeSigned (TBS) MD5e6d820afb23af20a65cf0b03247ea05e
    ToBeSigned (TBS) SHA17a8f7c37453f99390ee1e94bb5d3d1cba3a0eea7
    ToBeSigned (TBS) SHA2567e722dc40e6b9abf8c20aa4d887e34b6d2c6b8cbe53a055d49bf9f5e946e0d27
    SubjectC=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G3
    ValidFrom2012-05-01 00:00:00
    ValidTo2012-12-31 23:59:59
    Signature1e98aa27b778b508b5c9726db7dfc00e98a635c488c9d2f66df14b1afbd5f92d99009ed1e79b8be13fbd39800c66cd07bc5c9854a694ba10d14e8babf56f65cc6709a2807c52e80e03d66b7ac60518ecc8ac427c072ca73d0866dc00edfd941d73f2729893b111d68fef8eeaacf496510cd08ddf31524f5eaf7da74a75e64ece2b9f292be7cf5d9f037e6e277b23ad622966af92e82ccebd9c7fdccd173c43c2093f7545c79ee4d7607f97c6e4aac769f5fccd74ac2cb048c1504e70561eb535d38ebeb1edacbdfe0cec857dd5bb856644195d9f93eb82ba639ed37c61ffc81bd923587f30a366a139265e92c33ccb3732faf5a38ddcd5b0a3e9253655d781fa
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber79a2a585f9d1154213d9b83ef6b68ded
    Version3
    Certificate 47bf1995df8d524643f7db6d480d31a4
    FieldValue
    ToBeSigned (TBS) MD5518d2ea8a21e879c942d504824ac211c
    ToBeSigned (TBS) SHA121ce87d827077e61abddf2beba69fde5432ea031
    ToBeSigned (TBS) SHA2561ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA
    ValidFrom2003-12-04 00:00:00
    ValidTo2013-12-03 23:59:59
    Signature4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber47bf1995df8d524643f7db6d480d31a4
    Version3
    Certificate 655226e1b22e18e1590f2985ac22e75c
    FieldValue
    ToBeSigned (TBS) MD5650704c342850095f3288eaf791147d4
    ToBeSigned (TBS) SHA14cdc38c800761463749c3cbd94a12f32e49877bf
    ToBeSigned (TBS) SHA25607b8f662558ec85b71b43a79c6e94698144f4ced2308af21e7ba1e5d461da214
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA
    ValidFrom2009-05-21 00:00:00
    ValidTo2019-05-20 23:59:59
    Signature8b03c0dd94d841a26169b015a878c730c6903c7e42f724b6e4837317047f04109ca1e2fa812febc0ca44e772e050b6551020836e9692e49a516ab43731dca52deb8c00c71d4fe74d32ba85f84ebefa675565f06abe7aca64381a101078457631f3867a030f60c2b35d9df68b6676821b59e183e5bd49a53856e5de41770e580f
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber655226e1b22e18e1590f2985ac22e75c
    Version3
    Certificate 610c120600000000001b
    FieldValue
    ToBeSigned (TBS) MD553c41bc1164e09e0cd1617a5bf913efd
    ToBeSigned (TBS) SHA193c03aac8951d494ecd5696b1c08658541b18727
    ToBeSigned (TBS) SHA25640bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b
    SubjectC=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
    ValidFrom2006-05-23 17:01:29
    ValidTo2016-05-23 17:11:29
    Signature01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber610c120600000000001b
    Version3
    Certificate 25008956fcdc548a3079b096ef96c928
    FieldValue
    ToBeSigned (TBS) MD53bab1e250b6b9f2257ee7e262dfbcb65
    ToBeSigned (TBS) SHA1f99ffe487f507ecaa1874aedf700f26529baed68
    ToBeSigned (TBS) SHA2567273308094902ec5a0f89bcd6b8c487363c60ce6527c419dfa163e7f47c2f09d
    SubjectC=IT, ST=Padova, L=Rubano, O=TG Soft S.a.s. Di Tonello Gianfranco e C., OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=TG Soft S.a.s. Di Tonello Gianfranco e C.
    ValidFrom2010-01-15 00:00:00
    ValidTo2013-01-26 23:59:59
    Signature49acd6daead15fe8d7445a98d9c495f32e30c0bfe703acba889230d0e71911d319656ef50b2116f52fafc0e98010c27d23c59fc85bfd5a20c274a171279702f4c34435fe76b9746a39c64fd401aec55d0e1dedb33f6a8a4a35b3e4438ea30563562e3627df7abd77736982bd73966cd56b223a57e8cb3e709c316aa968eb8f9ef84560f0d68dc6e37ae179cca59e1ca21216cd04ac1f0913dbfb2ea258ebce38b3b329b2b9bd4dce4c6b568bebe1323e4622a0678ee5326540fbf0667684c9936eae2d879bb500e7f5684633e203cf5c9fcffad04ed7c712678d4209f32f280c1bf91b228a1d88a43f2b9cc0f68109b0ee81f935a87bfef1cf309fa7093a9c51
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber25008956fcdc548a3079b096ef96c928
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • mbstowcs
    • ExAllocatePoolWithTag
    • KeSetTargetProcessorDpc
    • ZwCreateKey
    • IoDeleteSymbolicLink
    • ExFreePoolWithTag
    • KeInitializeMutex
    • RtlAnsiStringToUnicodeString
    • ZwReadFile
    • RtlInitUnicodeString
    • IoDeleteDevice
    • RtlInitAnsiString
    • ZwSetValueKey
    • _strupr
    • KeInitializeDpc
    • ZwQuerySystemInformation
    • MmBuildMdlForNonPagedPool
    • IoFreeMdl
    • ZwSetInformationFile
    • KeReleaseMutex
    • KeDelayExecutionThread
    • ZwCreateFile
    • PsCreateSystemThread
    • MmMapLockedPagesSpecifyCache
    • ExSystemTimeToLocalTime
    • ZwQueryValueKey
    • PsTerminateSystemThread
    • KeInsertQueueDpc
    • ZwEnumerateValueKey
    • ZwClose
    • sprintf
    • ObReferenceObjectByHandle
    • KeWaitForSingleObject
    • RtlTimeToTimeFields
    • MmProbeAndLockPages
    • ZwOpenProcess
    • MmUnlockPages
    • IoCreateSymbolicLink
    • MmIsAddressValid
    • ObfDereferenceObject
    • IoCreateDevice
    • ZwTerminateProcess
    • wcstombs
    • KeNumberProcessors
    • ZwQueryInformationFile
    • MmIsNonPagedSystemAddressValid
    • ZwWriteFile
    • ZwDeleteKey
    • RtlFormatCurrentUserKeyPath
    • ZwEnumerateKey
    • IoAllocateMdl
    • ZwOpenKey
    • ObOpenObjectByName
    • swprintf
    • RtlUnicodeStringToAnsiString
    • ZwOpenDirectoryObject
    • IoFileObjectType
    • IoDriverObjectType
    • ZwQueryDirectoryObject
    • KeQueryActiveProcessors
    • KeBugCheckEx
    • IofCompleteRequest
    • ExQueueWorkItem
    • __C_specific_handler
    • __chkstk
    • KeStallExecutionProcessor

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "79a2a585f9d1154213d9b83ef6b68ded",
          "Signature": "1e98aa27b778b508b5c9726db7dfc00e98a635c488c9d2f66df14b1afbd5f92d99009ed1e79b8be13fbd39800c66cd07bc5c9854a694ba10d14e8babf56f65cc6709a2807c52e80e03d66b7ac60518ecc8ac427c072ca73d0866dc00edfd941d73f2729893b111d68fef8eeaacf496510cd08ddf31524f5eaf7da74a75e64ece2b9f292be7cf5d9f037e6e277b23ad622966af92e82ccebd9c7fdccd173c43c2093f7545c79ee4d7607f97c6e4aac769f5fccd74ac2cb048c1504e70561eb535d38ebeb1edacbdfe0cec857dd5bb856644195d9f93eb82ba639ed37c61ffc81bd923587f30a366a139265e92c33ccb3732faf5a38ddcd5b0a3e9253655d781fa",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G3",
          "TBS": {
            "MD5": "e6d820afb23af20a65cf0b03247ea05e",
            "SHA1": "7a8f7c37453f99390ee1e94bb5d3d1cba3a0eea7",
            "SHA256": "7e722dc40e6b9abf8c20aa4d887e34b6d2c6b8cbe53a055d49bf9f5e946e0d27",
            "SHA384": "7e14609969a388d38d227df1dbb9ce086c9a820142c94fd1a28ef2835a8aa528aef4c6399bce344d79adb5f3dad86afa"
          },
          "ValidFrom": "2012-05-01 00:00:00",
          "ValidTo": "2012-12-31 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "47bf1995df8d524643f7db6d480d31a4",
          "Signature": "4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA",
          "TBS": {
            "MD5": "518d2ea8a21e879c942d504824ac211c",
            "SHA1": "21ce87d827077e61abddf2beba69fde5432ea031",
            "SHA256": "1ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7",
            "SHA384": "53e346bbde23779a5d116cc9d86fdd71c97b1f1b343439f8a11aa1d3c87af63864bb8488a5aeb2d0c26a6a1e0b15f03f"
          },
          "ValidFrom": "2003-12-04 00:00:00",
          "ValidTo": "2013-12-03 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "655226e1b22e18e1590f2985ac22e75c",
          "Signature": "8b03c0dd94d841a26169b015a878c730c6903c7e42f724b6e4837317047f04109ca1e2fa812febc0ca44e772e050b6551020836e9692e49a516ab43731dca52deb8c00c71d4fe74d32ba85f84ebefa675565f06abe7aca64381a101078457631f3867a030f60c2b35d9df68b6676821b59e183e5bd49a53856e5de41770e580f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "TBS": {
            "MD5": "650704c342850095f3288eaf791147d4",
            "SHA1": "4cdc38c800761463749c3cbd94a12f32e49877bf",
            "SHA256": "07b8f662558ec85b71b43a79c6e94698144f4ced2308af21e7ba1e5d461da214",
            "SHA384": "2a271d052213438467d09d60eaa4010c8642fff3eb0070e0cf9969428713c8fdc066b90996d594dd3136f5bd0af5a22a"
          },
          "ValidFrom": "2009-05-21 00:00:00",
          "ValidTo": "2019-05-20 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610c120600000000001b",
          "Signature": "01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority",
          "TBS": {
            "MD5": "53c41bc1164e09e0cd1617a5bf913efd",
            "SHA1": "93c03aac8951d494ecd5696b1c08658541b18727",
            "SHA256": "40bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b",
            "SHA384": "f51d4e75ba638f7314cd59b8d6d45f3b34d35ce6986e9d205cd6f333e8e8d8e9c91f636e6bc84731b6661673f40963d8"
          },
          "ValidFrom": "2006-05-23 17:01:29",
          "ValidTo": "2016-05-23 17:11:29",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "25008956fcdc548a3079b096ef96c928",
          "Signature": "49acd6daead15fe8d7445a98d9c495f32e30c0bfe703acba889230d0e71911d319656ef50b2116f52fafc0e98010c27d23c59fc85bfd5a20c274a171279702f4c34435fe76b9746a39c64fd401aec55d0e1dedb33f6a8a4a35b3e4438ea30563562e3627df7abd77736982bd73966cd56b223a57e8cb3e709c316aa968eb8f9ef84560f0d68dc6e37ae179cca59e1ca21216cd04ac1f0913dbfb2ea258ebce38b3b329b2b9bd4dce4c6b568bebe1323e4622a0678ee5326540fbf0667684c9936eae2d879bb500e7f5684633e203cf5c9fcffad04ed7c712678d4209f32f280c1bf91b228a1d88a43f2b9cc0f68109b0ee81f935a87bfef1cf309fa7093a9c51",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=IT, ST=Padova, L=Rubano, O=TG Soft S.a.s. Di Tonello Gianfranco e C., OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=TG Soft S.a.s. Di Tonello Gianfranco e C.",
          "TBS": {
            "MD5": "3bab1e250b6b9f2257ee7e262dfbcb65",
            "SHA1": "f99ffe487f507ecaa1874aedf700f26529baed68",
            "SHA256": "7273308094902ec5a0f89bcd6b8c487363c60ce6527c419dfa163e7f47c2f09d",
            "SHA384": "55f33ea190b96f03dc48a54984dc6889f3b365e5f34e4bb80f4303ff60c8ad231226c5d45649a6091cbd96dfe735ad3a"
          },
          "ValidFrom": "2010-01-15 00:00:00",
          "ValidTo": "2013-01-26 23:59:59",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "SerialNumber": "25008956fcdc548a3079b096ef96c928",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filenameviragt.sys
    Creation Timestamp2010-11-30 01:59:42
    MD525ebe6f757129adbe78ec312a5f1800b
    SHA1d17656f11b899d58dca7b6c3dd6eef3d65ae88e2
    SHA256263e8f1e20612849aea95272da85773f577fd962a7a6d525b53f43407aa7ad24
    Authentihash MD578428144608ab49b0508197849200ab0
    Authentihash SHA1eb528a7bc5b0d9efe5872e16f42420291c6df07f
    Authentihash SHA25604f771d72a812fe9dd6bced402b36b081c80bd3397fdd66dbaa44906ac088159
    RichPEHeaderHash MD583156fdf8815d162dca182f334360c2c
    RichPEHeaderHash SHA11d222f1dcccbe673cd1f14eb1305f4f8ee5187c9
    RichPEHeaderHash SHA2567c182ba80bba313816b3138a0ad8b3e06306bdf22d80874913b0e75514bb9099
    CompanyTG Soft S.a.s.
    DescriptionVirIT Agent System
    ProductVirIT Agent System
    OriginalFilenameviragt.sys

    Download

    Certificates

    Expand
    Certificate 3825d7faf861af9ef490e726b5d65ad5
    FieldValue
    ToBeSigned (TBS) MD5d6c7684e9aaa508cf268335f83afe040
    ToBeSigned (TBS) SHA118066d20ad92409c567cdfde745279ff71c75226
    ToBeSigned (TBS) SHA256a612fb22ce8be6dab75e47c98508f98496583e79c9c97b936a8caee9ea9f3fff
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services Signer , G2
    ValidFrom2007-06-15 00:00:00
    ValidTo2012-06-14 23:59:59
    Signature50c54bc82480dfe40d24c2de1ab1a102a1a6822d0c831581370a820e2cb05a1761b5d805fe88dbf19191b3561a40a6eb92be3839b07536743a984fe437ba9989ca95421db0b9c7a08d57e0fad5640442354e01d133a217c84daa27c7f2e1864c02384d8378c6fc53e0ebe00687dda4969e5e0c98e2a5bebf8285c360e1dfad28d8c7a54b64dac71b5bbdac3908d53822a1338b2f8a9aebbc07213f44410907b5651c24bc48d34480eba1cfc902b414cf54c716a3805cf9793e5d727d88179e2c43a2ca53ce7d3df62a3ab84f9400a56d0a835df95e53f418b3570f70c3fbf5ad95a00e17dec4168060c90f2b6e8604f1ebf47827d105c5ee345b5eb94932f233
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber3825d7faf861af9ef490e726b5d65ad5
    Version3
    Certificate 47bf1995df8d524643f7db6d480d31a4
    FieldValue
    ToBeSigned (TBS) MD5518d2ea8a21e879c942d504824ac211c
    ToBeSigned (TBS) SHA121ce87d827077e61abddf2beba69fde5432ea031
    ToBeSigned (TBS) SHA2561ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA
    ValidFrom2003-12-04 00:00:00
    ValidTo2013-12-03 23:59:59
    Signature4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber47bf1995df8d524643f7db6d480d31a4
    Version3
    Certificate 655226e1b22e18e1590f2985ac22e75c
    FieldValue
    ToBeSigned (TBS) MD5650704c342850095f3288eaf791147d4
    ToBeSigned (TBS) SHA14cdc38c800761463749c3cbd94a12f32e49877bf
    ToBeSigned (TBS) SHA25607b8f662558ec85b71b43a79c6e94698144f4ced2308af21e7ba1e5d461da214
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA
    ValidFrom2009-05-21 00:00:00
    ValidTo2019-05-20 23:59:59
    Signature8b03c0dd94d841a26169b015a878c730c6903c7e42f724b6e4837317047f04109ca1e2fa812febc0ca44e772e050b6551020836e9692e49a516ab43731dca52deb8c00c71d4fe74d32ba85f84ebefa675565f06abe7aca64381a101078457631f3867a030f60c2b35d9df68b6676821b59e183e5bd49a53856e5de41770e580f
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber655226e1b22e18e1590f2985ac22e75c
    Version3
    Certificate 610c120600000000001b
    FieldValue
    ToBeSigned (TBS) MD553c41bc1164e09e0cd1617a5bf913efd
    ToBeSigned (TBS) SHA193c03aac8951d494ecd5696b1c08658541b18727
    ToBeSigned (TBS) SHA25640bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b
    SubjectC=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
    ValidFrom2006-05-23 17:01:29
    ValidTo2016-05-23 17:11:29
    Signature01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber610c120600000000001b
    Version3
    Certificate 25008956fcdc548a3079b096ef96c928
    FieldValue
    ToBeSigned (TBS) MD53bab1e250b6b9f2257ee7e262dfbcb65
    ToBeSigned (TBS) SHA1f99ffe487f507ecaa1874aedf700f26529baed68
    ToBeSigned (TBS) SHA2567273308094902ec5a0f89bcd6b8c487363c60ce6527c419dfa163e7f47c2f09d
    SubjectC=IT, ST=Padova, L=Rubano, O=TG Soft S.a.s. Di Tonello Gianfranco e C., OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=TG Soft S.a.s. Di Tonello Gianfranco e C.
    ValidFrom2010-01-15 00:00:00
    ValidTo2013-01-26 23:59:59
    Signature49acd6daead15fe8d7445a98d9c495f32e30c0bfe703acba889230d0e71911d319656ef50b2116f52fafc0e98010c27d23c59fc85bfd5a20c274a171279702f4c34435fe76b9746a39c64fd401aec55d0e1dedb33f6a8a4a35b3e4438ea30563562e3627df7abd77736982bd73966cd56b223a57e8cb3e709c316aa968eb8f9ef84560f0d68dc6e37ae179cca59e1ca21216cd04ac1f0913dbfb2ea258ebce38b3b329b2b9bd4dce4c6b568bebe1323e4622a0678ee5326540fbf0667684c9936eae2d879bb500e7f5684633e203cf5c9fcffad04ed7c712678d4209f32f280c1bf91b228a1d88a43f2b9cc0f68109b0ee81f935a87bfef1cf309fa7093a9c51
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber25008956fcdc548a3079b096ef96c928
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • ZwCreateKey
    • RtlAnsiStringToUnicodeString
    • RtlInitAnsiString
    • wcstombs
    • ZwOpenKey
    • ZwSetValueKey
    • ZwDeleteKey
    • RtlFormatCurrentUserKeyPath
    • ZwEnumerateKey
    • ZwEnumerateValueKey
    • ZwCreateFile
    • KeWaitForSingleObject
    • ObfDereferenceObject
    • ObReferenceObjectByHandle
    • ZwReadFile
    • ZwWriteFile
    • ZwSetInformationFile
    • ZwOpenProcess
    • ZwTerminateProcess
    • _strupr
    • ZwQuerySystemInformation
    • IoFreeMdl
    • MmUnlockPages
    • MmIsAddressValid
    • MmProbeAndLockPages
    • MmMapLockedPagesSpecifyCache
    • MmBuildMdlForNonPagedPool
    • IoAllocateMdl
    • MmIsNonPagedSystemAddressValid
    • IoGetCurrentProcess
    • PsLookupProcessByProcessId
    • IoDeleteDevice
    • ZwQueryValueKey
    • RtlInitUnicodeString
    • sprintf
    • RtlTimeToTimeFields
    • ExSystemTimeToLocalTime
    • KeQuerySystemTime
    • KeServiceDescriptorTable
    • KeReleaseMutex
    • KeDelayExecutionThread
    • PsTerminateSystemThread
    • ExQueueWorkItem
    • KeInsertQueueDpc
    • KeSetTargetProcessorDpc
    • KeInitializeDpc
    • KeNumberProcessors
    • IofCompleteRequest
    • memcpy
    • IoCreateSymbolicLink
    • IoCreateDevice
    • PsCreateSystemThread
    • KeInitializeMutex
    • ObOpenObjectByName
    • IoDriverObjectType
    • ZwOpenDirectoryObject
    • RtlUnicodeStringToAnsiString
    • ZwQueryDirectoryObject
    • KeTickCount
    • KeBugCheckEx
    • ExAllocatePoolWithTag
    • ExFreePoolWithTag
    • mbstowcs
    • ZwClose
    • memset
    • IoDeleteSymbolicLink
    • ZwQueryInformationFile
    • RtlUnwind
    • KfLowerIrql
    • KeGetCurrentIrql
    • READ_PORT_ULONG
    • WRITE_PORT_UCHAR
    • READ_PORT_UCHAR
    • READ_PORT_BUFFER_UCHAR
    • KfRaiseIrql

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "79a2a585f9d1154213d9b83ef6b68ded",
          "Signature": "1e98aa27b778b508b5c9726db7dfc00e98a635c488c9d2f66df14b1afbd5f92d99009ed1e79b8be13fbd39800c66cd07bc5c9854a694ba10d14e8babf56f65cc6709a2807c52e80e03d66b7ac60518ecc8ac427c072ca73d0866dc00edfd941d73f2729893b111d68fef8eeaacf496510cd08ddf31524f5eaf7da74a75e64ece2b9f292be7cf5d9f037e6e277b23ad622966af92e82ccebd9c7fdccd173c43c2093f7545c79ee4d7607f97c6e4aac769f5fccd74ac2cb048c1504e70561eb535d38ebeb1edacbdfe0cec857dd5bb856644195d9f93eb82ba639ed37c61ffc81bd923587f30a366a139265e92c33ccb3732faf5a38ddcd5b0a3e9253655d781fa",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G3",
          "TBS": {
            "MD5": "e6d820afb23af20a65cf0b03247ea05e",
            "SHA1": "7a8f7c37453f99390ee1e94bb5d3d1cba3a0eea7",
            "SHA256": "7e722dc40e6b9abf8c20aa4d887e34b6d2c6b8cbe53a055d49bf9f5e946e0d27",
            "SHA384": "7e14609969a388d38d227df1dbb9ce086c9a820142c94fd1a28ef2835a8aa528aef4c6399bce344d79adb5f3dad86afa"
          },
          "ValidFrom": "2012-05-01 00:00:00",
          "ValidTo": "2012-12-31 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "47bf1995df8d524643f7db6d480d31a4",
          "Signature": "4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA",
          "TBS": {
            "MD5": "518d2ea8a21e879c942d504824ac211c",
            "SHA1": "21ce87d827077e61abddf2beba69fde5432ea031",
            "SHA256": "1ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7",
            "SHA384": "53e346bbde23779a5d116cc9d86fdd71c97b1f1b343439f8a11aa1d3c87af63864bb8488a5aeb2d0c26a6a1e0b15f03f"
          },
          "ValidFrom": "2003-12-04 00:00:00",
          "ValidTo": "2013-12-03 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "655226e1b22e18e1590f2985ac22e75c",
          "Signature": "8b03c0dd94d841a26169b015a878c730c6903c7e42f724b6e4837317047f04109ca1e2fa812febc0ca44e772e050b6551020836e9692e49a516ab43731dca52deb8c00c71d4fe74d32ba85f84ebefa675565f06abe7aca64381a101078457631f3867a030f60c2b35d9df68b6676821b59e183e5bd49a53856e5de41770e580f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "TBS": {
            "MD5": "650704c342850095f3288eaf791147d4",
            "SHA1": "4cdc38c800761463749c3cbd94a12f32e49877bf",
            "SHA256": "07b8f662558ec85b71b43a79c6e94698144f4ced2308af21e7ba1e5d461da214",
            "SHA384": "2a271d052213438467d09d60eaa4010c8642fff3eb0070e0cf9969428713c8fdc066b90996d594dd3136f5bd0af5a22a"
          },
          "ValidFrom": "2009-05-21 00:00:00",
          "ValidTo": "2019-05-20 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610c120600000000001b",
          "Signature": "01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority",
          "TBS": {
            "MD5": "53c41bc1164e09e0cd1617a5bf913efd",
            "SHA1": "93c03aac8951d494ecd5696b1c08658541b18727",
            "SHA256": "40bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b",
            "SHA384": "f51d4e75ba638f7314cd59b8d6d45f3b34d35ce6986e9d205cd6f333e8e8d8e9c91f636e6bc84731b6661673f40963d8"
          },
          "ValidFrom": "2006-05-23 17:01:29",
          "ValidTo": "2016-05-23 17:11:29",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "25008956fcdc548a3079b096ef96c928",
          "Signature": "49acd6daead15fe8d7445a98d9c495f32e30c0bfe703acba889230d0e71911d319656ef50b2116f52fafc0e98010c27d23c59fc85bfd5a20c274a171279702f4c34435fe76b9746a39c64fd401aec55d0e1dedb33f6a8a4a35b3e4438ea30563562e3627df7abd77736982bd73966cd56b223a57e8cb3e709c316aa968eb8f9ef84560f0d68dc6e37ae179cca59e1ca21216cd04ac1f0913dbfb2ea258ebce38b3b329b2b9bd4dce4c6b568bebe1323e4622a0678ee5326540fbf0667684c9936eae2d879bb500e7f5684633e203cf5c9fcffad04ed7c712678d4209f32f280c1bf91b228a1d88a43f2b9cc0f68109b0ee81f935a87bfef1cf309fa7093a9c51",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=IT, ST=Padova, L=Rubano, O=TG Soft S.a.s. Di Tonello Gianfranco e C., OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=TG Soft S.a.s. Di Tonello Gianfranco e C.",
          "TBS": {
            "MD5": "3bab1e250b6b9f2257ee7e262dfbcb65",
            "SHA1": "f99ffe487f507ecaa1874aedf700f26529baed68",
            "SHA256": "7273308094902ec5a0f89bcd6b8c487363c60ce6527c419dfa163e7f47c2f09d",
            "SHA384": "55f33ea190b96f03dc48a54984dc6889f3b365e5f34e4bb80f4303ff60c8ad231226c5d45649a6091cbd96dfe735ad3a"
          },
          "ValidFrom": "2010-01-15 00:00:00",
          "ValidTo": "2013-01-26 23:59:59",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "SerialNumber": "25008956fcdc548a3079b096ef96c928",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filenameviragt.sys
    Creation Timestamp2012-07-30 09:03:12
    MD5650f6531db6fb0ed25d7fc70be35a4da
    SHA17ee675f0106e36d9159c5507b96c3237fb9348cd
    SHA2562a6212f3b68a6f263e96420b3607b31cfdfe51afff516f3c87d27bf8a89721e8
    Authentihash MD5fbbb02331ba15c59930554299f14b793
    Authentihash SHA12c300726f3806b6d077fe58ae8d2b257d654a700
    Authentihash SHA256f78e06f649bc0d88770c5465d7792abeb27631ec0ce9a0fa68698b94ebf2cf49
    RichPEHeaderHash MD549e861e9b5ef11a45073189555706b16
    RichPEHeaderHash SHA18b4484b05b022e8e3e31fd31af8d0375babefd7e
    RichPEHeaderHash SHA25679c8030870681fcb556c799112ac97f555ad4c5b81e30c73a57fb9090c2745dc
    CompanyTG Soft S.a.s.
    DescriptionVirIT Agent System
    ProductVirIT Agent System
    OriginalFilenameviragt.sys

    Download

    Certificates

    Expand
    Certificate 79a2a585f9d1154213d9b83ef6b68ded
    FieldValue
    ToBeSigned (TBS) MD5e6d820afb23af20a65cf0b03247ea05e
    ToBeSigned (TBS) SHA17a8f7c37453f99390ee1e94bb5d3d1cba3a0eea7
    ToBeSigned (TBS) SHA2567e722dc40e6b9abf8c20aa4d887e34b6d2c6b8cbe53a055d49bf9f5e946e0d27
    SubjectC=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G3
    ValidFrom2012-05-01 00:00:00
    ValidTo2012-12-31 23:59:59
    Signature1e98aa27b778b508b5c9726db7dfc00e98a635c488c9d2f66df14b1afbd5f92d99009ed1e79b8be13fbd39800c66cd07bc5c9854a694ba10d14e8babf56f65cc6709a2807c52e80e03d66b7ac60518ecc8ac427c072ca73d0866dc00edfd941d73f2729893b111d68fef8eeaacf496510cd08ddf31524f5eaf7da74a75e64ece2b9f292be7cf5d9f037e6e277b23ad622966af92e82ccebd9c7fdccd173c43c2093f7545c79ee4d7607f97c6e4aac769f5fccd74ac2cb048c1504e70561eb535d38ebeb1edacbdfe0cec857dd5bb856644195d9f93eb82ba639ed37c61ffc81bd923587f30a366a139265e92c33ccb3732faf5a38ddcd5b0a3e9253655d781fa
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber79a2a585f9d1154213d9b83ef6b68ded
    Version3
    Certificate 47bf1995df8d524643f7db6d480d31a4
    FieldValue
    ToBeSigned (TBS) MD5518d2ea8a21e879c942d504824ac211c
    ToBeSigned (TBS) SHA121ce87d827077e61abddf2beba69fde5432ea031
    ToBeSigned (TBS) SHA2561ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA
    ValidFrom2003-12-04 00:00:00
    ValidTo2013-12-03 23:59:59
    Signature4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber47bf1995df8d524643f7db6d480d31a4
    Version3
    Certificate 655226e1b22e18e1590f2985ac22e75c
    FieldValue
    ToBeSigned (TBS) MD5650704c342850095f3288eaf791147d4
    ToBeSigned (TBS) SHA14cdc38c800761463749c3cbd94a12f32e49877bf
    ToBeSigned (TBS) SHA25607b8f662558ec85b71b43a79c6e94698144f4ced2308af21e7ba1e5d461da214
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA
    ValidFrom2009-05-21 00:00:00
    ValidTo2019-05-20 23:59:59
    Signature8b03c0dd94d841a26169b015a878c730c6903c7e42f724b6e4837317047f04109ca1e2fa812febc0ca44e772e050b6551020836e9692e49a516ab43731dca52deb8c00c71d4fe74d32ba85f84ebefa675565f06abe7aca64381a101078457631f3867a030f60c2b35d9df68b6676821b59e183e5bd49a53856e5de41770e580f
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber655226e1b22e18e1590f2985ac22e75c
    Version3
    Certificate 610c120600000000001b
    FieldValue
    ToBeSigned (TBS) MD553c41bc1164e09e0cd1617a5bf913efd
    ToBeSigned (TBS) SHA193c03aac8951d494ecd5696b1c08658541b18727
    ToBeSigned (TBS) SHA25640bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b
    SubjectC=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
    ValidFrom2006-05-23 17:01:29
    ValidTo2016-05-23 17:11:29
    Signature01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber610c120600000000001b
    Version3
    Certificate 25008956fcdc548a3079b096ef96c928
    FieldValue
    ToBeSigned (TBS) MD53bab1e250b6b9f2257ee7e262dfbcb65
    ToBeSigned (TBS) SHA1f99ffe487f507ecaa1874aedf700f26529baed68
    ToBeSigned (TBS) SHA2567273308094902ec5a0f89bcd6b8c487363c60ce6527c419dfa163e7f47c2f09d
    SubjectC=IT, ST=Padova, L=Rubano, O=TG Soft S.a.s. Di Tonello Gianfranco e C., OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=TG Soft S.a.s. Di Tonello Gianfranco e C.
    ValidFrom2010-01-15 00:00:00
    ValidTo2013-01-26 23:59:59
    Signature49acd6daead15fe8d7445a98d9c495f32e30c0bfe703acba889230d0e71911d319656ef50b2116f52fafc0e98010c27d23c59fc85bfd5a20c274a171279702f4c34435fe76b9746a39c64fd401aec55d0e1dedb33f6a8a4a35b3e4438ea30563562e3627df7abd77736982bd73966cd56b223a57e8cb3e709c316aa968eb8f9ef84560f0d68dc6e37ae179cca59e1ca21216cd04ac1f0913dbfb2ea258ebce38b3b329b2b9bd4dce4c6b568bebe1323e4622a0678ee5326540fbf0667684c9936eae2d879bb500e7f5684633e203cf5c9fcffad04ed7c712678d4209f32f280c1bf91b228a1d88a43f2b9cc0f68109b0ee81f935a87bfef1cf309fa7093a9c51
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber25008956fcdc548a3079b096ef96c928
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • RtlInitAnsiString
    • wcstombs
    • ZwOpenKey
    • ZwSetValueKey
    • ZwDeleteKey
    • RtlFormatCurrentUserKeyPath
    • ZwEnumerateKey
    • ZwEnumerateValueKey
    • ZwCreateFile
    • KeWaitForSingleObject
    • IofCallDriver
    • IoBuildSynchronousFsdRequest
    • KeInitializeEvent
    • ObfDereferenceObject
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ZwReadFile
    • ZwWriteFile
    • ZwSetInformationFile
    • ZwOpenProcess
    • ZwTerminateProcess
    • _strupr
    • ZwQuerySystemInformation
    • IoFreeMdl
    • MmUnlockPages
    • MmIsAddressValid
    • MmProbeAndLockPages
    • MmMapLockedPagesSpecifyCache
    • MmBuildMdlForNonPagedPool
    • IoAllocateMdl
    • MmIsNonPagedSystemAddressValid
    • IoGetCurrentProcess
    • PsLookupProcessByProcessId
    • IoDeleteDevice
    • IoDeleteSymbolicLink
    • RtlInitUnicodeString
    • sprintf
    • RtlTimeToTimeFields
    • ExSystemTimeToLocalTime
    • KeQuerySystemTime
    • KeServiceDescriptorTable
    • KeReleaseMutex
    • KeDelayExecutionThread
    • RtlAnsiStringToUnicodeString
    • ExQueueWorkItem
    • KeInsertQueueDpc
    • KeSetTargetProcessorDpc
    • KeInitializeDpc
    • KeNumberProcessors
    • IofCompleteRequest
    • memcpy
    • IoCreateSymbolicLink
    • IoCreateDevice
    • PsCreateSystemThread
    • KeInitializeMutex
    • ObOpenObjectByName
    • IoDriverObjectType
    • ZwOpenDirectoryObject
    • RtlUnicodeStringToAnsiString
    • ZwQueryDirectoryObject
    • IoFileObjectType
    • swprintf
    • DbgPrint
    • IoFreeIrp
    • MmUnmapLockedPages
    • KeSetEvent
    • MmLockPagableSectionByHandle
    • MmLockPagableDataSection
    • IoAllocateIrp
    • _wcsnicmp
    • RtlCompareMemory
    • IoBuildDeviceIoControlRequest
    • _alldiv
    • wcsrchr
    • ZwQueryVolumeInformationFile
    • ZwDeviceIoControlFile
    • _strnicmp
    • ZwFsControlFile
    • _allmul
    • ObfReferenceObject
    • _allrem
    • _stricmp
    • strrchr
    • KeQueryActiveProcessors
    • KeTickCount
    • KeBugCheckEx
    • ZwCreateKey
    • ZwQueryValueKey
    • ExAllocatePoolWithTag
    • ExFreePoolWithTag
    • mbstowcs
    • ZwClose
    • memset
    • PsTerminateSystemThread
    • ZwQueryInformationFile
    • RtlUnwind
    • KeRaiseIrqlToDpcLevel
    • KfRaiseIrql
    • KfLowerIrql
    • KeGetCurrentIrql
    • READ_PORT_ULONG
    • WRITE_PORT_UCHAR
    • READ_PORT_UCHAR
    • READ_PORT_BUFFER_UCHAR
    • KeStallExecutionProcessor

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • NonPaged
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "79a2a585f9d1154213d9b83ef6b68ded",
          "Signature": "1e98aa27b778b508b5c9726db7dfc00e98a635c488c9d2f66df14b1afbd5f92d99009ed1e79b8be13fbd39800c66cd07bc5c9854a694ba10d14e8babf56f65cc6709a2807c52e80e03d66b7ac60518ecc8ac427c072ca73d0866dc00edfd941d73f2729893b111d68fef8eeaacf496510cd08ddf31524f5eaf7da74a75e64ece2b9f292be7cf5d9f037e6e277b23ad622966af92e82ccebd9c7fdccd173c43c2093f7545c79ee4d7607f97c6e4aac769f5fccd74ac2cb048c1504e70561eb535d38ebeb1edacbdfe0cec857dd5bb856644195d9f93eb82ba639ed37c61ffc81bd923587f30a366a139265e92c33ccb3732faf5a38ddcd5b0a3e9253655d781fa",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G3",
          "TBS": {
            "MD5": "e6d820afb23af20a65cf0b03247ea05e",
            "SHA1": "7a8f7c37453f99390ee1e94bb5d3d1cba3a0eea7",
            "SHA256": "7e722dc40e6b9abf8c20aa4d887e34b6d2c6b8cbe53a055d49bf9f5e946e0d27",
            "SHA384": "7e14609969a388d38d227df1dbb9ce086c9a820142c94fd1a28ef2835a8aa528aef4c6399bce344d79adb5f3dad86afa"
          },
          "ValidFrom": "2012-05-01 00:00:00",
          "ValidTo": "2012-12-31 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "47bf1995df8d524643f7db6d480d31a4",
          "Signature": "4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA",
          "TBS": {
            "MD5": "518d2ea8a21e879c942d504824ac211c",
            "SHA1": "21ce87d827077e61abddf2beba69fde5432ea031",
            "SHA256": "1ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7",
            "SHA384": "53e346bbde23779a5d116cc9d86fdd71c97b1f1b343439f8a11aa1d3c87af63864bb8488a5aeb2d0c26a6a1e0b15f03f"
          },
          "ValidFrom": "2003-12-04 00:00:00",
          "ValidTo": "2013-12-03 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "655226e1b22e18e1590f2985ac22e75c",
          "Signature": "8b03c0dd94d841a26169b015a878c730c6903c7e42f724b6e4837317047f04109ca1e2fa812febc0ca44e772e050b6551020836e9692e49a516ab43731dca52deb8c00c71d4fe74d32ba85f84ebefa675565f06abe7aca64381a101078457631f3867a030f60c2b35d9df68b6676821b59e183e5bd49a53856e5de41770e580f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "TBS": {
            "MD5": "650704c342850095f3288eaf791147d4",
            "SHA1": "4cdc38c800761463749c3cbd94a12f32e49877bf",
            "SHA256": "07b8f662558ec85b71b43a79c6e94698144f4ced2308af21e7ba1e5d461da214",
            "SHA384": "2a271d052213438467d09d60eaa4010c8642fff3eb0070e0cf9969428713c8fdc066b90996d594dd3136f5bd0af5a22a"
          },
          "ValidFrom": "2009-05-21 00:00:00",
          "ValidTo": "2019-05-20 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610c120600000000001b",
          "Signature": "01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority",
          "TBS": {
            "MD5": "53c41bc1164e09e0cd1617a5bf913efd",
            "SHA1": "93c03aac8951d494ecd5696b1c08658541b18727",
            "SHA256": "40bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b",
            "SHA384": "f51d4e75ba638f7314cd59b8d6d45f3b34d35ce6986e9d205cd6f333e8e8d8e9c91f636e6bc84731b6661673f40963d8"
          },
          "ValidFrom": "2006-05-23 17:01:29",
          "ValidTo": "2016-05-23 17:11:29",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "25008956fcdc548a3079b096ef96c928",
          "Signature": "49acd6daead15fe8d7445a98d9c495f32e30c0bfe703acba889230d0e71911d319656ef50b2116f52fafc0e98010c27d23c59fc85bfd5a20c274a171279702f4c34435fe76b9746a39c64fd401aec55d0e1dedb33f6a8a4a35b3e4438ea30563562e3627df7abd77736982bd73966cd56b223a57e8cb3e709c316aa968eb8f9ef84560f0d68dc6e37ae179cca59e1ca21216cd04ac1f0913dbfb2ea258ebce38b3b329b2b9bd4dce4c6b568bebe1323e4622a0678ee5326540fbf0667684c9936eae2d879bb500e7f5684633e203cf5c9fcffad04ed7c712678d4209f32f280c1bf91b228a1d88a43f2b9cc0f68109b0ee81f935a87bfef1cf309fa7093a9c51",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=IT, ST=Padova, L=Rubano, O=TG Soft S.a.s. Di Tonello Gianfranco e C., OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=TG Soft S.a.s. Di Tonello Gianfranco e C.",
          "TBS": {
            "MD5": "3bab1e250b6b9f2257ee7e262dfbcb65",
            "SHA1": "f99ffe487f507ecaa1874aedf700f26529baed68",
            "SHA256": "7273308094902ec5a0f89bcd6b8c487363c60ce6527c419dfa163e7f47c2f09d",
            "SHA384": "55f33ea190b96f03dc48a54984dc6889f3b365e5f34e4bb80f4303ff60c8ad231226c5d45649a6091cbd96dfe735ad3a"
          },
          "ValidFrom": "2010-01-15 00:00:00",
          "ValidTo": "2013-01-26 23:59:59",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "SerialNumber": "25008956fcdc548a3079b096ef96c928",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filenameviragt.sys
    Creation Timestamp2013-11-29 04:59:32
    MD53467b0d996251dc56a72fc51a536dd6b
    SHA1ca33c88cd74e00ece898dca32a24bdfcacc3f756
    SHA2562b4c7d3820fe08400a7791e2556132b902a9bbadc1942de57077ecb9d21bf47a
    Authentihash MD5e39802ea77fa83f1939a50985f9036c0
    Authentihash SHA1070c6795aa64c2bce7867e280016fb1d2af86dca
    Authentihash SHA256ac42c7b1d9feccd48c305698942186d580b7bfd047bb73dbf028f3fed7aa24ad
    RichPEHeaderHash MD5fd47e50698bf05f04850340b52ac1853
    RichPEHeaderHash SHA1ee25f84fd5c60f82580743dfaab31e2e5e1fbe30
    RichPEHeaderHash SHA25644490b82f96dcb06373c259b6532d209604916c484dccba49970a77732bd9906
    CompanyTG Soft S.a.s.
    DescriptionVirIT Agent System
    ProductVirIT Agent System
    OriginalFilenameviragt.sys

    Download

    Certificates

    Expand
    Certificate 7e93ebfb7cc64e59ea4b9a77d406fc3b
    FieldValue
    ToBeSigned (TBS) MD5d0785ad36e427c92b19f6826ab1e8020
    ToBeSigned (TBS) SHA1365b7a9c21bd9373e49052c3e7b3e4646ddd4d43
    ToBeSigned (TBS) SHA256c2abb7484da91a658548de089d52436175fdb760a1387d225611dc0613a1e2ff
    SubjectC=US, O=Symantec Corporation, CN=Symantec Time Stamping Services CA , G2
    ValidFrom2012-12-21 00:00:00
    ValidTo2020-12-30 23:59:59
    Signature03099b8f79ef7f5930aaef68b5fae3091dbb4f82065d375fa6529f168dea1c9209446ef56deb587c30e8f9698d23730b126f47a9ae3911f82ab19bb01ac38eeb599600adce0c4db2d031a6085c2a7afce27a1d574ca86518e979406225966ec7c7376a8321088e41eaddd9573f1d7749872a16065ea6386a2212a35119837eb6
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber7e93ebfb7cc64e59ea4b9a77d406fc3b
    Version3
    Certificate 0ecff438c8febf356e04d86a981b1a50
    FieldValue
    ToBeSigned (TBS) MD5e9d38360b914c8863f6cba3ee58764d3
    ToBeSigned (TBS) SHA14cba8eae47b6bf76f20b3504b98b8f062694a89b
    ToBeSigned (TBS) SHA25688901d86a4cc1f1bb193d08e1fb63d27452e63f83e228c657ab1a92e4ade3976
    SubjectC=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G4
    ValidFrom2012-10-18 00:00:00
    ValidTo2020-12-29 23:59:59
    Signature783bb4912a004cf08f62303778a38427076f18b2de25dca0d49403aa864e259f9a40031cddcee379cb216806dab632b46dbff42c266333e449646d0de6c3670ef705a4356c7c8916c6e9b2dfb2e9dd20c6710fcd9574dcb65cdebd371f4378e678b5cd280420a3aaf14bc48829910e80d111fcdd5c766e4f5e0e4546416e0db0ea389ab13ada097110fc1c79b4807bac69f4fd9cb60c162bf17f5b093d9b5be216ca13816d002e380da8298f2ce1b2f45aa901af159c2c2f491bdb22bbc3fe789451c386b182885df03db451a179332b2e7bb9dc20091371eb6a195bcfe8a530572c89493fb9cf7fc9bf3e226863539abd6974acc51d3c7f92e0c3bc1cd80475
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber0ecff438c8febf356e04d86a981b1a50
    Version3
    Certificate 250ce8e030612e9f2b89f7054d7cf8fd
    FieldValue
    ToBeSigned (TBS) MD5918d9eb6a6cd36c531eceb926170a7e1
    ToBeSigned (TBS) SHA10ae95700d65e6f59715aa47048993ca7858e676a
    ToBeSigned (TBS) SHA25647c46e6eaa3780eace3d0d891346cd373359d246b21a957219dbab4c8f37c166
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. , For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority , G5
    ValidFrom2006-11-08 00:00:00
    ValidTo2021-11-07 23:59:59
    Signature1302ddf8e88600f25af8f8200c59886207cecef74ef9bb59a198e5e138dd4ebc6618d3adeb18f20dc96d3e4a9420c33cbabd6554c6af44b310ad2c6b3eabd707b6b88163c5f95e2ee52a67cecd330c2ad7895603231fb3bee83a0859b4ec4535f78a5bff66cf50afc66d578d1978b7b9a2d157ea1f9a4bafbac98e127ec6bdff
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber250ce8e030612e9f2b89f7054d7cf8fd
    Version3
    Certificate 610c120600000000001b
    FieldValue
    ToBeSigned (TBS) MD553c41bc1164e09e0cd1617a5bf913efd
    ToBeSigned (TBS) SHA193c03aac8951d494ecd5696b1c08658541b18727
    ToBeSigned (TBS) SHA25640bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b
    SubjectC=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
    ValidFrom2006-05-23 17:01:29
    ValidTo2016-05-23 17:11:29
    Signature01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber610c120600000000001b
    Version3
    Certificate 4cccaccf48f6d93fb37178d7fce6209c
    FieldValue
    ToBeSigned (TBS) MD51f0b47e6661a3261d4c982b2eb35b0ec
    ToBeSigned (TBS) SHA18320a06969446f33184f8a25a91942870a5a54d5
    ToBeSigned (TBS) SHA25615e095f260d9ceca3f947817c1f53ddf687e32438d55a51be1b66785183e9840
    SubjectC=IT, ST=Padova, L=Rubano, O=TG Soft S.a.s. Di Tonello Gianfranco e C., OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=TG Soft S.a.s. Di Tonello Gianfranco e C.
    ValidFrom2012-12-31 00:00:00
    ValidTo2016-02-29 23:59:59
    Signaturec7c9efc50350a4c32f6dacc513ba6ac9fe5fd749bd74dcb912bdc41655a751ecd628c0d94677c4bc71424ba27a3b82680532cb0fa85f6d7ae2a5a9b5a0f2c87059ce4c5c80c426bafe6fa0713e23787b5fe5274c659c221a58a376d27d9866a1843d21788bc53012b5af4b9a8787b5a6dd2d41498e60967e5248c6cc8b08ccafc5f39006f0597ae03b91f0aed26337f40550dc1fe4490df7258d2f0bdf0448d5a68c3bb8222007b91f9f83e4813edfb134738bfdd5c5cd9f8413b360231472ec5a22d32e7c6e15b127a34f84edea31ce625a0c87aaa07e31a14221dc51689e68e5a0e13bd563475134ee102e1a86788dc909dbdb4c7a370e0d418c8424e88a14
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber4cccaccf48f6d93fb37178d7fce6209c
    Version3
    Certificate 5200e5aa2556fc1a86ed96c9d44b33c7
    FieldValue
    ToBeSigned (TBS) MD5b30c31a572b0409383ed3fbe17e56e81
    ToBeSigned (TBS) SHA14843a82ed3b1f2bfbee9671960e1940c942f688d
    ToBeSigned (TBS) SHA25603cda47a6e654ed85d932714fc09ce4874600eda29ec6628cfbaeb155cab78c9
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 Code Signing 2010 CA
    ValidFrom2010-02-08 00:00:00
    ValidTo2020-02-07 23:59:59
    Signature5622e634a4c461cb48b901ad56a8640fd98c91c4bbcc0ce5ad7aa0227fdf47384a2d6cd17f711a7cec70a9b1f04fe40f0c53fa155efe749849248581261c911447b04c638cbba134d4c645e80d85267303d0a98c646ddc7192e645056015595139fc58146bfed4a4ed796b080c4172e737220609be23e93f449a1ee9619dccb1905cfc3dd28dac423d6536d4b43d40288f9b10cf2326cc4b20cb901f5d8c4c34ca3cd8e537d66fa520bd34eb26d9ae0de7c59af7a1b42191336f86e858bb257c740e58fe751b633fce317c9b8f1b969ec55376845b9cad91faaced93ba5dc82153c2825363af120d5087111b3d5452968a2c9c3d921a089a052ec793a54891d3
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber5200e5aa2556fc1a86ed96c9d44b33c7
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • RtlInitAnsiString
    • wcstombs
    • ZwOpenKey
    • ZwSetValueKey
    • ZwDeleteKey
    • RtlFormatCurrentUserKeyPath
    • ZwEnumerateKey
    • ZwEnumerateValueKey
    • ZwCreateFile
    • KeWaitForSingleObject
    • IofCallDriver
    • IoBuildSynchronousFsdRequest
    • KeInitializeEvent
    • ObfDereferenceObject
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ZwReadFile
    • ZwWriteFile
    • ZwSetInformationFile
    • ZwOpenProcess
    • ZwTerminateProcess
    • _strupr
    • ZwQuerySystemInformation
    • IoFreeMdl
    • MmUnlockPages
    • MmIsAddressValid
    • MmProbeAndLockPages
    • MmMapLockedPagesSpecifyCache
    • MmBuildMdlForNonPagedPool
    • IoAllocateMdl
    • MmIsNonPagedSystemAddressValid
    • IoGetCurrentProcess
    • PsLookupProcessByProcessId
    • IoDeleteDevice
    • IoDeleteSymbolicLink
    • RtlInitUnicodeString
    • sprintf
    • RtlTimeToTimeFields
    • ExSystemTimeToLocalTime
    • KeQuerySystemTime
    • strstr
    • KeServiceDescriptorTable
    • KeReleaseMutex
    • KeDelayExecutionThread
    • RtlAnsiStringToUnicodeString
    • ExQueueWorkItem
    • KeInsertQueueDpc
    • KeSetTargetProcessorDpc
    • KeInitializeDpc
    • KeNumberProcessors
    • IofCompleteRequest
    • PsCreateSystemThread
    • memcpy
    • IoCreateSymbolicLink
    • IoCreateDevice
    • KeInitializeMutex
    • RtlUnicodeStringToAnsiString
    • IoGetDeviceObjectPointer
    • ObOpenObjectByName
    • IoDriverObjectType
    • ZwOpenDirectoryObject
    • ZwQueryDirectoryObject
    • IoFileObjectType
    • swprintf
    • DbgPrint
    • IoFreeIrp
    • MmUnmapLockedPages
    • KeSetEvent
    • MmLockPagableSectionByHandle
    • MmLockPagableDataSection
    • IoAllocateIrp
    • _wcsnicmp
    • RtlCompareMemory
    • IoBuildDeviceIoControlRequest
    • _alldiv
    • wcsrchr
    • ZwQueryVolumeInformationFile
    • ZwDeviceIoControlFile
    • _strnicmp
    • ZwFsControlFile
    • _allmul
    • ObfReferenceObject
    • _allrem
    • _stricmp
    • strrchr
    • KeQueryActiveProcessors
    • KeTickCount
    • KeBugCheckEx
    • ZwCreateKey
    • ZwQueryValueKey
    • ExAllocatePoolWithTag
    • ExFreePoolWithTag
    • mbstowcs
    • ZwClose
    • memset
    • PsTerminateSystemThread
    • ZwQueryInformationFile
    • RtlUnwind
    • KeRaiseIrqlToDpcLevel
    • KfRaiseIrql
    • KfLowerIrql
    • KeGetCurrentIrql
    • READ_PORT_ULONG
    • WRITE_PORT_UCHAR
    • READ_PORT_UCHAR
    • READ_PORT_BUFFER_UCHAR
    • KeStallExecutionProcessor

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • NonPaged
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "79a2a585f9d1154213d9b83ef6b68ded",
          "Signature": "1e98aa27b778b508b5c9726db7dfc00e98a635c488c9d2f66df14b1afbd5f92d99009ed1e79b8be13fbd39800c66cd07bc5c9854a694ba10d14e8babf56f65cc6709a2807c52e80e03d66b7ac60518ecc8ac427c072ca73d0866dc00edfd941d73f2729893b111d68fef8eeaacf496510cd08ddf31524f5eaf7da74a75e64ece2b9f292be7cf5d9f037e6e277b23ad622966af92e82ccebd9c7fdccd173c43c2093f7545c79ee4d7607f97c6e4aac769f5fccd74ac2cb048c1504e70561eb535d38ebeb1edacbdfe0cec857dd5bb856644195d9f93eb82ba639ed37c61ffc81bd923587f30a366a139265e92c33ccb3732faf5a38ddcd5b0a3e9253655d781fa",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G3",
          "TBS": {
            "MD5": "e6d820afb23af20a65cf0b03247ea05e",
            "SHA1": "7a8f7c37453f99390ee1e94bb5d3d1cba3a0eea7",
            "SHA256": "7e722dc40e6b9abf8c20aa4d887e34b6d2c6b8cbe53a055d49bf9f5e946e0d27",
            "SHA384": "7e14609969a388d38d227df1dbb9ce086c9a820142c94fd1a28ef2835a8aa528aef4c6399bce344d79adb5f3dad86afa"
          },
          "ValidFrom": "2012-05-01 00:00:00",
          "ValidTo": "2012-12-31 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "47bf1995df8d524643f7db6d480d31a4",
          "Signature": "4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA",
          "TBS": {
            "MD5": "518d2ea8a21e879c942d504824ac211c",
            "SHA1": "21ce87d827077e61abddf2beba69fde5432ea031",
            "SHA256": "1ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7",
            "SHA384": "53e346bbde23779a5d116cc9d86fdd71c97b1f1b343439f8a11aa1d3c87af63864bb8488a5aeb2d0c26a6a1e0b15f03f"
          },
          "ValidFrom": "2003-12-04 00:00:00",
          "ValidTo": "2013-12-03 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "655226e1b22e18e1590f2985ac22e75c",
          "Signature": "8b03c0dd94d841a26169b015a878c730c6903c7e42f724b6e4837317047f04109ca1e2fa812febc0ca44e772e050b6551020836e9692e49a516ab43731dca52deb8c00c71d4fe74d32ba85f84ebefa675565f06abe7aca64381a101078457631f3867a030f60c2b35d9df68b6676821b59e183e5bd49a53856e5de41770e580f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "TBS": {
            "MD5": "650704c342850095f3288eaf791147d4",
            "SHA1": "4cdc38c800761463749c3cbd94a12f32e49877bf",
            "SHA256": "07b8f662558ec85b71b43a79c6e94698144f4ced2308af21e7ba1e5d461da214",
            "SHA384": "2a271d052213438467d09d60eaa4010c8642fff3eb0070e0cf9969428713c8fdc066b90996d594dd3136f5bd0af5a22a"
          },
          "ValidFrom": "2009-05-21 00:00:00",
          "ValidTo": "2019-05-20 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610c120600000000001b",
          "Signature": "01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority",
          "TBS": {
            "MD5": "53c41bc1164e09e0cd1617a5bf913efd",
            "SHA1": "93c03aac8951d494ecd5696b1c08658541b18727",
            "SHA256": "40bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b",
            "SHA384": "f51d4e75ba638f7314cd59b8d6d45f3b34d35ce6986e9d205cd6f333e8e8d8e9c91f636e6bc84731b6661673f40963d8"
          },
          "ValidFrom": "2006-05-23 17:01:29",
          "ValidTo": "2016-05-23 17:11:29",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "25008956fcdc548a3079b096ef96c928",
          "Signature": "49acd6daead15fe8d7445a98d9c495f32e30c0bfe703acba889230d0e71911d319656ef50b2116f52fafc0e98010c27d23c59fc85bfd5a20c274a171279702f4c34435fe76b9746a39c64fd401aec55d0e1dedb33f6a8a4a35b3e4438ea30563562e3627df7abd77736982bd73966cd56b223a57e8cb3e709c316aa968eb8f9ef84560f0d68dc6e37ae179cca59e1ca21216cd04ac1f0913dbfb2ea258ebce38b3b329b2b9bd4dce4c6b568bebe1323e4622a0678ee5326540fbf0667684c9936eae2d879bb500e7f5684633e203cf5c9fcffad04ed7c712678d4209f32f280c1bf91b228a1d88a43f2b9cc0f68109b0ee81f935a87bfef1cf309fa7093a9c51",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=IT, ST=Padova, L=Rubano, O=TG Soft S.a.s. Di Tonello Gianfranco e C., OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=TG Soft S.a.s. Di Tonello Gianfranco e C.",
          "TBS": {
            "MD5": "3bab1e250b6b9f2257ee7e262dfbcb65",
            "SHA1": "f99ffe487f507ecaa1874aedf700f26529baed68",
            "SHA256": "7273308094902ec5a0f89bcd6b8c487363c60ce6527c419dfa163e7f47c2f09d",
            "SHA384": "55f33ea190b96f03dc48a54984dc6889f3b365e5f34e4bb80f4303ff60c8ad231226c5d45649a6091cbd96dfe735ad3a"
          },
          "ValidFrom": "2010-01-15 00:00:00",
          "ValidTo": "2013-01-26 23:59:59",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "SerialNumber": "25008956fcdc548a3079b096ef96c928",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filenameviragt64.sys
    Creation Timestamp2013-01-23 01:42:36
    MD5688a10e87af9bcf0e40277d927923a00
    SHA1388819a7048179848425441c60b3a8390ad04a69
    SHA2569b2f051ac901ab47d0012a1002cb8b2db28c14e9480c0dd55e1ac11c81ba9285
    Authentihash MD52a499183392f0d3835f957bbe6b538ba
    Authentihash SHA1f8a9a8d7c704069d4fff9c26740115c1f4ba3499
    Authentihash SHA256605e0efa14fc8443dc43c2068f17e6f175369909d5f7f1c3730fb5fe062528e6
    RichPEHeaderHash MD5a93c261e407f22e8e9e11096ef7669a4
    RichPEHeaderHash SHA1579ea1a06578ca54a9b86ccfa3c06b3be01831bf
    RichPEHeaderHash SHA256b566c96b0a5ca93fe5cdd066966b85657108a1cc6eadb0b683932c781d3a3510
    CompanyTG Soft S.a.s.
    DescriptionVirIT Agent System
    ProductVirIT Agent System
    OriginalFilenameviragt64.sys

    Download

    Certificates

    Expand
    Certificate 7e93ebfb7cc64e59ea4b9a77d406fc3b
    FieldValue
    ToBeSigned (TBS) MD5d0785ad36e427c92b19f6826ab1e8020
    ToBeSigned (TBS) SHA1365b7a9c21bd9373e49052c3e7b3e4646ddd4d43
    ToBeSigned (TBS) SHA256c2abb7484da91a658548de089d52436175fdb760a1387d225611dc0613a1e2ff
    SubjectC=US, O=Symantec Corporation, CN=Symantec Time Stamping Services CA , G2
    ValidFrom2012-12-21 00:00:00
    ValidTo2020-12-30 23:59:59
    Signature03099b8f79ef7f5930aaef68b5fae3091dbb4f82065d375fa6529f168dea1c9209446ef56deb587c30e8f9698d23730b126f47a9ae3911f82ab19bb01ac38eeb599600adce0c4db2d031a6085c2a7afce27a1d574ca86518e979406225966ec7c7376a8321088e41eaddd9573f1d7749872a16065ea6386a2212a35119837eb6
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber7e93ebfb7cc64e59ea4b9a77d406fc3b
    Version3
    Certificate 0ecff438c8febf356e04d86a981b1a50
    FieldValue
    ToBeSigned (TBS) MD5e9d38360b914c8863f6cba3ee58764d3
    ToBeSigned (TBS) SHA14cba8eae47b6bf76f20b3504b98b8f062694a89b
    ToBeSigned (TBS) SHA25688901d86a4cc1f1bb193d08e1fb63d27452e63f83e228c657ab1a92e4ade3976
    SubjectC=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G4
    ValidFrom2012-10-18 00:00:00
    ValidTo2020-12-29 23:59:59
    Signature783bb4912a004cf08f62303778a38427076f18b2de25dca0d49403aa864e259f9a40031cddcee379cb216806dab632b46dbff42c266333e449646d0de6c3670ef705a4356c7c8916c6e9b2dfb2e9dd20c6710fcd9574dcb65cdebd371f4378e678b5cd280420a3aaf14bc48829910e80d111fcdd5c766e4f5e0e4546416e0db0ea389ab13ada097110fc1c79b4807bac69f4fd9cb60c162bf17f5b093d9b5be216ca13816d002e380da8298f2ce1b2f45aa901af159c2c2f491bdb22bbc3fe789451c386b182885df03db451a179332b2e7bb9dc20091371eb6a195bcfe8a530572c89493fb9cf7fc9bf3e226863539abd6974acc51d3c7f92e0c3bc1cd80475
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber0ecff438c8febf356e04d86a981b1a50
    Version3
    Certificate 250ce8e030612e9f2b89f7054d7cf8fd
    FieldValue
    ToBeSigned (TBS) MD5918d9eb6a6cd36c531eceb926170a7e1
    ToBeSigned (TBS) SHA10ae95700d65e6f59715aa47048993ca7858e676a
    ToBeSigned (TBS) SHA25647c46e6eaa3780eace3d0d891346cd373359d246b21a957219dbab4c8f37c166
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. , For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority , G5
    ValidFrom2006-11-08 00:00:00
    ValidTo2021-11-07 23:59:59
    Signature1302ddf8e88600f25af8f8200c59886207cecef74ef9bb59a198e5e138dd4ebc6618d3adeb18f20dc96d3e4a9420c33cbabd6554c6af44b310ad2c6b3eabd707b6b88163c5f95e2ee52a67cecd330c2ad7895603231fb3bee83a0859b4ec4535f78a5bff66cf50afc66d578d1978b7b9a2d157ea1f9a4bafbac98e127ec6bdff
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber250ce8e030612e9f2b89f7054d7cf8fd
    Version3
    Certificate 610c120600000000001b
    FieldValue
    ToBeSigned (TBS) MD553c41bc1164e09e0cd1617a5bf913efd
    ToBeSigned (TBS) SHA193c03aac8951d494ecd5696b1c08658541b18727
    ToBeSigned (TBS) SHA25640bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b
    SubjectC=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
    ValidFrom2006-05-23 17:01:29
    ValidTo2016-05-23 17:11:29
    Signature01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber610c120600000000001b
    Version3
    Certificate 4cccaccf48f6d93fb37178d7fce6209c
    FieldValue
    ToBeSigned (TBS) MD51f0b47e6661a3261d4c982b2eb35b0ec
    ToBeSigned (TBS) SHA18320a06969446f33184f8a25a91942870a5a54d5
    ToBeSigned (TBS) SHA25615e095f260d9ceca3f947817c1f53ddf687e32438d55a51be1b66785183e9840
    SubjectC=IT, ST=Padova, L=Rubano, O=TG Soft S.a.s. Di Tonello Gianfranco e C., OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=TG Soft S.a.s. Di Tonello Gianfranco e C.
    ValidFrom2012-12-31 00:00:00
    ValidTo2016-02-29 23:59:59
    Signaturec7c9efc50350a4c32f6dacc513ba6ac9fe5fd749bd74dcb912bdc41655a751ecd628c0d94677c4bc71424ba27a3b82680532cb0fa85f6d7ae2a5a9b5a0f2c87059ce4c5c80c426bafe6fa0713e23787b5fe5274c659c221a58a376d27d9866a1843d21788bc53012b5af4b9a8787b5a6dd2d41498e60967e5248c6cc8b08ccafc5f39006f0597ae03b91f0aed26337f40550dc1fe4490df7258d2f0bdf0448d5a68c3bb8222007b91f9f83e4813edfb134738bfdd5c5cd9f8413b360231472ec5a22d32e7c6e15b127a34f84edea31ce625a0c87aaa07e31a14221dc51689e68e5a0e13bd563475134ee102e1a86788dc909dbdb4c7a370e0d418c8424e88a14
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber4cccaccf48f6d93fb37178d7fce6209c
    Version3
    Certificate 5200e5aa2556fc1a86ed96c9d44b33c7
    FieldValue
    ToBeSigned (TBS) MD5b30c31a572b0409383ed3fbe17e56e81
    ToBeSigned (TBS) SHA14843a82ed3b1f2bfbee9671960e1940c942f688d
    ToBeSigned (TBS) SHA25603cda47a6e654ed85d932714fc09ce4874600eda29ec6628cfbaeb155cab78c9
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 Code Signing 2010 CA
    ValidFrom2010-02-08 00:00:00
    ValidTo2020-02-07 23:59:59
    Signature5622e634a4c461cb48b901ad56a8640fd98c91c4bbcc0ce5ad7aa0227fdf47384a2d6cd17f711a7cec70a9b1f04fe40f0c53fa155efe749849248581261c911447b04c638cbba134d4c645e80d85267303d0a98c646ddc7192e645056015595139fc58146bfed4a4ed796b080c4172e737220609be23e93f449a1ee9619dccb1905cfc3dd28dac423d6536d4b43d40288f9b10cf2326cc4b20cb901f5d8c4c34ca3cd8e537d66fa520bd34eb26d9ae0de7c59af7a1b42191336f86e858bb257c740e58fe751b633fce317c9b8f1b969ec55376845b9cad91faaced93ba5dc82153c2825363af120d5087111b3d5452968a2c9c3d921a089a052ec793a54891d3
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber5200e5aa2556fc1a86ed96c9d44b33c7
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • mbstowcs
    • ExAllocatePoolWithTag
    • KeSetTargetProcessorDpc
    • ZwCreateKey
    • IoDeleteSymbolicLink
    • ExFreePoolWithTag
    • KeInitializeMutex
    • RtlAnsiStringToUnicodeString
    • ZwReadFile
    • strstr
    • RtlInitUnicodeString
    • IoDeleteDevice
    • RtlInitAnsiString
    • ZwSetValueKey
    • _strupr
    • KeInitializeDpc
    • ZwQuerySystemInformation
    • MmBuildMdlForNonPagedPool
    • IoFreeMdl
    • ZwSetInformationFile
    • KeReleaseMutex
    • KeDelayExecutionThread
    • ZwCreateFile
    • PsCreateSystemThread
    • MmMapLockedPagesSpecifyCache
    • ExSystemTimeToLocalTime
    • ZwQueryValueKey
    • PsTerminateSystemThread
    • KeInsertQueueDpc
    • ZwEnumerateValueKey
    • ZwClose
    • sprintf
    • ObReferenceObjectByHandle
    • KeWaitForSingleObject
    • RtlTimeToTimeFields
    • MmProbeAndLockPages
    • ZwOpenProcess
    • MmUnlockPages
    • IoCreateSymbolicLink
    • MmIsAddressValid
    • ObfDereferenceObject
    • IoCreateDevice
    • ZwTerminateProcess
    • KeNumberProcessors
    • ZwQueryInformationFile
    • MmIsNonPagedSystemAddressValid
    • ZwWriteFile
    • ZwDeleteKey
    • RtlFormatCurrentUserKeyPath
    • ZwEnumerateKey
    • IoAllocateMdl
    • ZwOpenKey
    • ObOpenObjectByName
    • swprintf
    • RtlUnicodeStringToAnsiString
    • ZwOpenDirectoryObject
    • IoFileObjectType
    • IoDriverObjectType
    • ZwQueryDirectoryObject
    • wcstombs
    • KeQueryActiveProcessors
    • KeBugCheckEx
    • IofCompleteRequest
    • ExQueueWorkItem
    • __C_specific_handler
    • __chkstk
    • KeStallExecutionProcessor

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "79a2a585f9d1154213d9b83ef6b68ded",
          "Signature": "1e98aa27b778b508b5c9726db7dfc00e98a635c488c9d2f66df14b1afbd5f92d99009ed1e79b8be13fbd39800c66cd07bc5c9854a694ba10d14e8babf56f65cc6709a2807c52e80e03d66b7ac60518ecc8ac427c072ca73d0866dc00edfd941d73f2729893b111d68fef8eeaacf496510cd08ddf31524f5eaf7da74a75e64ece2b9f292be7cf5d9f037e6e277b23ad622966af92e82ccebd9c7fdccd173c43c2093f7545c79ee4d7607f97c6e4aac769f5fccd74ac2cb048c1504e70561eb535d38ebeb1edacbdfe0cec857dd5bb856644195d9f93eb82ba639ed37c61ffc81bd923587f30a366a139265e92c33ccb3732faf5a38ddcd5b0a3e9253655d781fa",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G3",
          "TBS": {
            "MD5": "e6d820afb23af20a65cf0b03247ea05e",
            "SHA1": "7a8f7c37453f99390ee1e94bb5d3d1cba3a0eea7",
            "SHA256": "7e722dc40e6b9abf8c20aa4d887e34b6d2c6b8cbe53a055d49bf9f5e946e0d27",
            "SHA384": "7e14609969a388d38d227df1dbb9ce086c9a820142c94fd1a28ef2835a8aa528aef4c6399bce344d79adb5f3dad86afa"
          },
          "ValidFrom": "2012-05-01 00:00:00",
          "ValidTo": "2012-12-31 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "47bf1995df8d524643f7db6d480d31a4",
          "Signature": "4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA",
          "TBS": {
            "MD5": "518d2ea8a21e879c942d504824ac211c",
            "SHA1": "21ce87d827077e61abddf2beba69fde5432ea031",
            "SHA256": "1ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7",
            "SHA384": "53e346bbde23779a5d116cc9d86fdd71c97b1f1b343439f8a11aa1d3c87af63864bb8488a5aeb2d0c26a6a1e0b15f03f"
          },
          "ValidFrom": "2003-12-04 00:00:00",
          "ValidTo": "2013-12-03 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "655226e1b22e18e1590f2985ac22e75c",
          "Signature": "8b03c0dd94d841a26169b015a878c730c6903c7e42f724b6e4837317047f04109ca1e2fa812febc0ca44e772e050b6551020836e9692e49a516ab43731dca52deb8c00c71d4fe74d32ba85f84ebefa675565f06abe7aca64381a101078457631f3867a030f60c2b35d9df68b6676821b59e183e5bd49a53856e5de41770e580f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "TBS": {
            "MD5": "650704c342850095f3288eaf791147d4",
            "SHA1": "4cdc38c800761463749c3cbd94a12f32e49877bf",
            "SHA256": "07b8f662558ec85b71b43a79c6e94698144f4ced2308af21e7ba1e5d461da214",
            "SHA384": "2a271d052213438467d09d60eaa4010c8642fff3eb0070e0cf9969428713c8fdc066b90996d594dd3136f5bd0af5a22a"
          },
          "ValidFrom": "2009-05-21 00:00:00",
          "ValidTo": "2019-05-20 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610c120600000000001b",
          "Signature": "01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority",
          "TBS": {
            "MD5": "53c41bc1164e09e0cd1617a5bf913efd",
            "SHA1": "93c03aac8951d494ecd5696b1c08658541b18727",
            "SHA256": "40bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b",
            "SHA384": "f51d4e75ba638f7314cd59b8d6d45f3b34d35ce6986e9d205cd6f333e8e8d8e9c91f636e6bc84731b6661673f40963d8"
          },
          "ValidFrom": "2006-05-23 17:01:29",
          "ValidTo": "2016-05-23 17:11:29",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "25008956fcdc548a3079b096ef96c928",
          "Signature": "49acd6daead15fe8d7445a98d9c495f32e30c0bfe703acba889230d0e71911d319656ef50b2116f52fafc0e98010c27d23c59fc85bfd5a20c274a171279702f4c34435fe76b9746a39c64fd401aec55d0e1dedb33f6a8a4a35b3e4438ea30563562e3627df7abd77736982bd73966cd56b223a57e8cb3e709c316aa968eb8f9ef84560f0d68dc6e37ae179cca59e1ca21216cd04ac1f0913dbfb2ea258ebce38b3b329b2b9bd4dce4c6b568bebe1323e4622a0678ee5326540fbf0667684c9936eae2d879bb500e7f5684633e203cf5c9fcffad04ed7c712678d4209f32f280c1bf91b228a1d88a43f2b9cc0f68109b0ee81f935a87bfef1cf309fa7093a9c51",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=IT, ST=Padova, L=Rubano, O=TG Soft S.a.s. Di Tonello Gianfranco e C., OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=TG Soft S.a.s. Di Tonello Gianfranco e C.",
          "TBS": {
            "MD5": "3bab1e250b6b9f2257ee7e262dfbcb65",
            "SHA1": "f99ffe487f507ecaa1874aedf700f26529baed68",
            "SHA256": "7273308094902ec5a0f89bcd6b8c487363c60ce6527c419dfa163e7f47c2f09d",
            "SHA384": "55f33ea190b96f03dc48a54984dc6889f3b365e5f34e4bb80f4303ff60c8ad231226c5d45649a6091cbd96dfe735ad3a"
          },
          "ValidFrom": "2010-01-15 00:00:00",
          "ValidTo": "2013-01-26 23:59:59",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "SerialNumber": "25008956fcdc548a3079b096ef96c928",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filenameviragt.sys
    Creation Timestamp2011-12-29 10:38:08
    MD53d5164e85d740bce0391e2b81d49d308
    SHA17ce978092fadbef44441a5f8dcb434df2464f193
    SHA256d0e25b879d830e4f867b09d6540a664b6f88bad353cd14494c33b31a8091f605
    Authentihash MD5fca297e7088250ac73298a7d623e1137
    Authentihash SHA1d1d6535cd02ff50825941130fe992fcdc91c71cd
    Authentihash SHA256401ed2d2768707b5c47556774c119f989986a9e2fa88e1e2626f14e22b85e66b
    RichPEHeaderHash MD549e861e9b5ef11a45073189555706b16
    RichPEHeaderHash SHA18b4484b05b022e8e3e31fd31af8d0375babefd7e
    RichPEHeaderHash SHA25679c8030870681fcb556c799112ac97f555ad4c5b81e30c73a57fb9090c2745dc
    CompanyTG Soft S.a.s.
    DescriptionVirIT Agent System
    ProductVirIT Agent System
    OriginalFilenameviragt.sys

    Download

    Certificates

    Expand
    Certificate 3825d7faf861af9ef490e726b5d65ad5
    FieldValue
    ToBeSigned (TBS) MD5d6c7684e9aaa508cf268335f83afe040
    ToBeSigned (TBS) SHA118066d20ad92409c567cdfde745279ff71c75226
    ToBeSigned (TBS) SHA256a612fb22ce8be6dab75e47c98508f98496583e79c9c97b936a8caee9ea9f3fff
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services Signer , G2
    ValidFrom2007-06-15 00:00:00
    ValidTo2012-06-14 23:59:59
    Signature50c54bc82480dfe40d24c2de1ab1a102a1a6822d0c831581370a820e2cb05a1761b5d805fe88dbf19191b3561a40a6eb92be3839b07536743a984fe437ba9989ca95421db0b9c7a08d57e0fad5640442354e01d133a217c84daa27c7f2e1864c02384d8378c6fc53e0ebe00687dda4969e5e0c98e2a5bebf8285c360e1dfad28d8c7a54b64dac71b5bbdac3908d53822a1338b2f8a9aebbc07213f44410907b5651c24bc48d34480eba1cfc902b414cf54c716a3805cf9793e5d727d88179e2c43a2ca53ce7d3df62a3ab84f9400a56d0a835df95e53f418b3570f70c3fbf5ad95a00e17dec4168060c90f2b6e8604f1ebf47827d105c5ee345b5eb94932f233
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber3825d7faf861af9ef490e726b5d65ad5
    Version3
    Certificate 47bf1995df8d524643f7db6d480d31a4
    FieldValue
    ToBeSigned (TBS) MD5518d2ea8a21e879c942d504824ac211c
    ToBeSigned (TBS) SHA121ce87d827077e61abddf2beba69fde5432ea031
    ToBeSigned (TBS) SHA2561ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA
    ValidFrom2003-12-04 00:00:00
    ValidTo2013-12-03 23:59:59
    Signature4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber47bf1995df8d524643f7db6d480d31a4
    Version3
    Certificate 655226e1b22e18e1590f2985ac22e75c
    FieldValue
    ToBeSigned (TBS) MD5650704c342850095f3288eaf791147d4
    ToBeSigned (TBS) SHA14cdc38c800761463749c3cbd94a12f32e49877bf
    ToBeSigned (TBS) SHA25607b8f662558ec85b71b43a79c6e94698144f4ced2308af21e7ba1e5d461da214
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA
    ValidFrom2009-05-21 00:00:00
    ValidTo2019-05-20 23:59:59
    Signature8b03c0dd94d841a26169b015a878c730c6903c7e42f724b6e4837317047f04109ca1e2fa812febc0ca44e772e050b6551020836e9692e49a516ab43731dca52deb8c00c71d4fe74d32ba85f84ebefa675565f06abe7aca64381a101078457631f3867a030f60c2b35d9df68b6676821b59e183e5bd49a53856e5de41770e580f
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber655226e1b22e18e1590f2985ac22e75c
    Version3
    Certificate 610c120600000000001b
    FieldValue
    ToBeSigned (TBS) MD553c41bc1164e09e0cd1617a5bf913efd
    ToBeSigned (TBS) SHA193c03aac8951d494ecd5696b1c08658541b18727
    ToBeSigned (TBS) SHA25640bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b
    SubjectC=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
    ValidFrom2006-05-23 17:01:29
    ValidTo2016-05-23 17:11:29
    Signature01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber610c120600000000001b
    Version3
    Certificate 25008956fcdc548a3079b096ef96c928
    FieldValue
    ToBeSigned (TBS) MD53bab1e250b6b9f2257ee7e262dfbcb65
    ToBeSigned (TBS) SHA1f99ffe487f507ecaa1874aedf700f26529baed68
    ToBeSigned (TBS) SHA2567273308094902ec5a0f89bcd6b8c487363c60ce6527c419dfa163e7f47c2f09d
    SubjectC=IT, ST=Padova, L=Rubano, O=TG Soft S.a.s. Di Tonello Gianfranco e C., OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=TG Soft S.a.s. Di Tonello Gianfranco e C.
    ValidFrom2010-01-15 00:00:00
    ValidTo2013-01-26 23:59:59
    Signature49acd6daead15fe8d7445a98d9c495f32e30c0bfe703acba889230d0e71911d319656ef50b2116f52fafc0e98010c27d23c59fc85bfd5a20c274a171279702f4c34435fe76b9746a39c64fd401aec55d0e1dedb33f6a8a4a35b3e4438ea30563562e3627df7abd77736982bd73966cd56b223a57e8cb3e709c316aa968eb8f9ef84560f0d68dc6e37ae179cca59e1ca21216cd04ac1f0913dbfb2ea258ebce38b3b329b2b9bd4dce4c6b568bebe1323e4622a0678ee5326540fbf0667684c9936eae2d879bb500e7f5684633e203cf5c9fcffad04ed7c712678d4209f32f280c1bf91b228a1d88a43f2b9cc0f68109b0ee81f935a87bfef1cf309fa7093a9c51
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber25008956fcdc548a3079b096ef96c928
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • RtlInitAnsiString
    • wcstombs
    • ZwOpenKey
    • ZwSetValueKey
    • ZwDeleteKey
    • RtlFormatCurrentUserKeyPath
    • ZwEnumerateKey
    • ZwEnumerateValueKey
    • ZwCreateFile
    • KeWaitForSingleObject
    • IofCallDriver
    • IoBuildSynchronousFsdRequest
    • KeInitializeEvent
    • ObfDereferenceObject
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ZwReadFile
    • ZwWriteFile
    • ZwSetInformationFile
    • ZwOpenProcess
    • ZwTerminateProcess
    • _strupr
    • ZwQuerySystemInformation
    • IoFreeMdl
    • MmUnlockPages
    • MmIsAddressValid
    • MmProbeAndLockPages
    • MmMapLockedPagesSpecifyCache
    • MmBuildMdlForNonPagedPool
    • IoAllocateMdl
    • MmIsNonPagedSystemAddressValid
    • IoGetCurrentProcess
    • PsLookupProcessByProcessId
    • IoDeleteDevice
    • IoDeleteSymbolicLink
    • RtlInitUnicodeString
    • sprintf
    • RtlTimeToTimeFields
    • ExSystemTimeToLocalTime
    • KeQuerySystemTime
    • KeServiceDescriptorTable
    • KeReleaseMutex
    • KeDelayExecutionThread
    • RtlAnsiStringToUnicodeString
    • ExQueueWorkItem
    • KeInsertQueueDpc
    • KeSetTargetProcessorDpc
    • KeInitializeDpc
    • KeNumberProcessors
    • IofCompleteRequest
    • memcpy
    • IoCreateSymbolicLink
    • IoCreateDevice
    • PsCreateSystemThread
    • KeInitializeMutex
    • ObOpenObjectByName
    • IoDriverObjectType
    • ZwOpenDirectoryObject
    • RtlUnicodeStringToAnsiString
    • ZwQueryDirectoryObject
    • DbgPrint
    • IoFileObjectType
    • swprintf
    • IoFreeIrp
    • MmUnmapLockedPages
    • KeSetEvent
    • MmLockPagableSectionByHandle
    • MmLockPagableDataSection
    • IoAllocateIrp
    • _wcsnicmp
    • RtlCompareMemory
    • IoBuildDeviceIoControlRequest
    • _alldiv
    • wcsrchr
    • ZwQueryVolumeInformationFile
    • ZwDeviceIoControlFile
    • _strnicmp
    • ZwFsControlFile
    • _allmul
    • ObfReferenceObject
    • _allrem
    • _stricmp
    • strrchr
    • KeQueryActiveProcessors
    • KeTickCount
    • KeBugCheckEx
    • ZwCreateKey
    • ZwQueryValueKey
    • ExAllocatePoolWithTag
    • ExFreePoolWithTag
    • mbstowcs
    • ZwClose
    • memset
    • PsTerminateSystemThread
    • ZwQueryInformationFile
    • RtlUnwind
    • KeRaiseIrqlToDpcLevel
    • KfRaiseIrql
    • KfLowerIrql
    • KeGetCurrentIrql
    • READ_PORT_ULONG
    • WRITE_PORT_UCHAR
    • READ_PORT_UCHAR
    • READ_PORT_BUFFER_UCHAR
    • KeStallExecutionProcessor

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • NonPaged
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "79a2a585f9d1154213d9b83ef6b68ded",
          "Signature": "1e98aa27b778b508b5c9726db7dfc00e98a635c488c9d2f66df14b1afbd5f92d99009ed1e79b8be13fbd39800c66cd07bc5c9854a694ba10d14e8babf56f65cc6709a2807c52e80e03d66b7ac60518ecc8ac427c072ca73d0866dc00edfd941d73f2729893b111d68fef8eeaacf496510cd08ddf31524f5eaf7da74a75e64ece2b9f292be7cf5d9f037e6e277b23ad622966af92e82ccebd9c7fdccd173c43c2093f7545c79ee4d7607f97c6e4aac769f5fccd74ac2cb048c1504e70561eb535d38ebeb1edacbdfe0cec857dd5bb856644195d9f93eb82ba639ed37c61ffc81bd923587f30a366a139265e92c33ccb3732faf5a38ddcd5b0a3e9253655d781fa",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G3",
          "TBS": {
            "MD5": "e6d820afb23af20a65cf0b03247ea05e",
            "SHA1": "7a8f7c37453f99390ee1e94bb5d3d1cba3a0eea7",
            "SHA256": "7e722dc40e6b9abf8c20aa4d887e34b6d2c6b8cbe53a055d49bf9f5e946e0d27",
            "SHA384": "7e14609969a388d38d227df1dbb9ce086c9a820142c94fd1a28ef2835a8aa528aef4c6399bce344d79adb5f3dad86afa"
          },
          "ValidFrom": "2012-05-01 00:00:00",
          "ValidTo": "2012-12-31 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "47bf1995df8d524643f7db6d480d31a4",
          "Signature": "4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA",
          "TBS": {
            "MD5": "518d2ea8a21e879c942d504824ac211c",
            "SHA1": "21ce87d827077e61abddf2beba69fde5432ea031",
            "SHA256": "1ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7",
            "SHA384": "53e346bbde23779a5d116cc9d86fdd71c97b1f1b343439f8a11aa1d3c87af63864bb8488a5aeb2d0c26a6a1e0b15f03f"
          },
          "ValidFrom": "2003-12-04 00:00:00",
          "ValidTo": "2013-12-03 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "655226e1b22e18e1590f2985ac22e75c",
          "Signature": "8b03c0dd94d841a26169b015a878c730c6903c7e42f724b6e4837317047f04109ca1e2fa812febc0ca44e772e050b6551020836e9692e49a516ab43731dca52deb8c00c71d4fe74d32ba85f84ebefa675565f06abe7aca64381a101078457631f3867a030f60c2b35d9df68b6676821b59e183e5bd49a53856e5de41770e580f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "TBS": {
            "MD5": "650704c342850095f3288eaf791147d4",
            "SHA1": "4cdc38c800761463749c3cbd94a12f32e49877bf",
            "SHA256": "07b8f662558ec85b71b43a79c6e94698144f4ced2308af21e7ba1e5d461da214",
            "SHA384": "2a271d052213438467d09d60eaa4010c8642fff3eb0070e0cf9969428713c8fdc066b90996d594dd3136f5bd0af5a22a"
          },
          "ValidFrom": "2009-05-21 00:00:00",
          "ValidTo": "2019-05-20 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610c120600000000001b",
          "Signature": "01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority",
          "TBS": {
            "MD5": "53c41bc1164e09e0cd1617a5bf913efd",
            "SHA1": "93c03aac8951d494ecd5696b1c08658541b18727",
            "SHA256": "40bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b",
            "SHA384": "f51d4e75ba638f7314cd59b8d6d45f3b34d35ce6986e9d205cd6f333e8e8d8e9c91f636e6bc84731b6661673f40963d8"
          },
          "ValidFrom": "2006-05-23 17:01:29",
          "ValidTo": "2016-05-23 17:11:29",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "25008956fcdc548a3079b096ef96c928",
          "Signature": "49acd6daead15fe8d7445a98d9c495f32e30c0bfe703acba889230d0e71911d319656ef50b2116f52fafc0e98010c27d23c59fc85bfd5a20c274a171279702f4c34435fe76b9746a39c64fd401aec55d0e1dedb33f6a8a4a35b3e4438ea30563562e3627df7abd77736982bd73966cd56b223a57e8cb3e709c316aa968eb8f9ef84560f0d68dc6e37ae179cca59e1ca21216cd04ac1f0913dbfb2ea258ebce38b3b329b2b9bd4dce4c6b568bebe1323e4622a0678ee5326540fbf0667684c9936eae2d879bb500e7f5684633e203cf5c9fcffad04ed7c712678d4209f32f280c1bf91b228a1d88a43f2b9cc0f68109b0ee81f935a87bfef1cf309fa7093a9c51",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=IT, ST=Padova, L=Rubano, O=TG Soft S.a.s. Di Tonello Gianfranco e C., OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=TG Soft S.a.s. Di Tonello Gianfranco e C.",
          "TBS": {
            "MD5": "3bab1e250b6b9f2257ee7e262dfbcb65",
            "SHA1": "f99ffe487f507ecaa1874aedf700f26529baed68",
            "SHA256": "7273308094902ec5a0f89bcd6b8c487363c60ce6527c419dfa163e7f47c2f09d",
            "SHA384": "55f33ea190b96f03dc48a54984dc6889f3b365e5f34e4bb80f4303ff60c8ad231226c5d45649a6091cbd96dfe735ad3a"
          },
          "ValidFrom": "2010-01-15 00:00:00",
          "ValidTo": "2013-01-26 23:59:59",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "SerialNumber": "25008956fcdc548a3079b096ef96c928",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filenameviragt.sys
    Creation Timestamp2011-05-10 10:33:08
    MD53ad7b36a584504b3c70b5f552ba33015
    SHA1d363011d6991219d7f152609164aba63c266b740
    SHA256e4eca7db365929ff7c5c785e2eab04ef8ec67ea9edcf7392f2b74eccd9449148
    Authentihash MD5bec44ba7f52a8c4700876db0c566d696
    Authentihash SHA13854d0364d7379bcb7d59311823cadc3e34d1612
    Authentihash SHA256230fe99d425e870cc03383b195d5a8c0ef3d191baaa4104f6f4cdee4960c48fc
    RichPEHeaderHash MD549e861e9b5ef11a45073189555706b16
    RichPEHeaderHash SHA18b4484b05b022e8e3e31fd31af8d0375babefd7e
    RichPEHeaderHash SHA25679c8030870681fcb556c799112ac97f555ad4c5b81e30c73a57fb9090c2745dc
    CompanyTG Soft S.a.s.
    DescriptionVirIT Agent System
    ProductVirIT Agent System
    OriginalFilenameviragt.sys

    Download

    Certificates

    Expand
    Certificate 3825d7faf861af9ef490e726b5d65ad5
    FieldValue
    ToBeSigned (TBS) MD5d6c7684e9aaa508cf268335f83afe040
    ToBeSigned (TBS) SHA118066d20ad92409c567cdfde745279ff71c75226
    ToBeSigned (TBS) SHA256a612fb22ce8be6dab75e47c98508f98496583e79c9c97b936a8caee9ea9f3fff
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services Signer , G2
    ValidFrom2007-06-15 00:00:00
    ValidTo2012-06-14 23:59:59
    Signature50c54bc82480dfe40d24c2de1ab1a102a1a6822d0c831581370a820e2cb05a1761b5d805fe88dbf19191b3561a40a6eb92be3839b07536743a984fe437ba9989ca95421db0b9c7a08d57e0fad5640442354e01d133a217c84daa27c7f2e1864c02384d8378c6fc53e0ebe00687dda4969e5e0c98e2a5bebf8285c360e1dfad28d8c7a54b64dac71b5bbdac3908d53822a1338b2f8a9aebbc07213f44410907b5651c24bc48d34480eba1cfc902b414cf54c716a3805cf9793e5d727d88179e2c43a2ca53ce7d3df62a3ab84f9400a56d0a835df95e53f418b3570f70c3fbf5ad95a00e17dec4168060c90f2b6e8604f1ebf47827d105c5ee345b5eb94932f233
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber3825d7faf861af9ef490e726b5d65ad5
    Version3
    Certificate 47bf1995df8d524643f7db6d480d31a4
    FieldValue
    ToBeSigned (TBS) MD5518d2ea8a21e879c942d504824ac211c
    ToBeSigned (TBS) SHA121ce87d827077e61abddf2beba69fde5432ea031
    ToBeSigned (TBS) SHA2561ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA
    ValidFrom2003-12-04 00:00:00
    ValidTo2013-12-03 23:59:59
    Signature4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber47bf1995df8d524643f7db6d480d31a4
    Version3
    Certificate 655226e1b22e18e1590f2985ac22e75c
    FieldValue
    ToBeSigned (TBS) MD5650704c342850095f3288eaf791147d4
    ToBeSigned (TBS) SHA14cdc38c800761463749c3cbd94a12f32e49877bf
    ToBeSigned (TBS) SHA25607b8f662558ec85b71b43a79c6e94698144f4ced2308af21e7ba1e5d461da214
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA
    ValidFrom2009-05-21 00:00:00
    ValidTo2019-05-20 23:59:59
    Signature8b03c0dd94d841a26169b015a878c730c6903c7e42f724b6e4837317047f04109ca1e2fa812febc0ca44e772e050b6551020836e9692e49a516ab43731dca52deb8c00c71d4fe74d32ba85f84ebefa675565f06abe7aca64381a101078457631f3867a030f60c2b35d9df68b6676821b59e183e5bd49a53856e5de41770e580f
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber655226e1b22e18e1590f2985ac22e75c
    Version3
    Certificate 610c120600000000001b
    FieldValue
    ToBeSigned (TBS) MD553c41bc1164e09e0cd1617a5bf913efd
    ToBeSigned (TBS) SHA193c03aac8951d494ecd5696b1c08658541b18727
    ToBeSigned (TBS) SHA25640bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b
    SubjectC=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
    ValidFrom2006-05-23 17:01:29
    ValidTo2016-05-23 17:11:29
    Signature01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber610c120600000000001b
    Version3
    Certificate 25008956fcdc548a3079b096ef96c928
    FieldValue
    ToBeSigned (TBS) MD53bab1e250b6b9f2257ee7e262dfbcb65
    ToBeSigned (TBS) SHA1f99ffe487f507ecaa1874aedf700f26529baed68
    ToBeSigned (TBS) SHA2567273308094902ec5a0f89bcd6b8c487363c60ce6527c419dfa163e7f47c2f09d
    SubjectC=IT, ST=Padova, L=Rubano, O=TG Soft S.a.s. Di Tonello Gianfranco e C., OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=TG Soft S.a.s. Di Tonello Gianfranco e C.
    ValidFrom2010-01-15 00:00:00
    ValidTo2013-01-26 23:59:59
    Signature49acd6daead15fe8d7445a98d9c495f32e30c0bfe703acba889230d0e71911d319656ef50b2116f52fafc0e98010c27d23c59fc85bfd5a20c274a171279702f4c34435fe76b9746a39c64fd401aec55d0e1dedb33f6a8a4a35b3e4438ea30563562e3627df7abd77736982bd73966cd56b223a57e8cb3e709c316aa968eb8f9ef84560f0d68dc6e37ae179cca59e1ca21216cd04ac1f0913dbfb2ea258ebce38b3b329b2b9bd4dce4c6b568bebe1323e4622a0678ee5326540fbf0667684c9936eae2d879bb500e7f5684633e203cf5c9fcffad04ed7c712678d4209f32f280c1bf91b228a1d88a43f2b9cc0f68109b0ee81f935a87bfef1cf309fa7093a9c51
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber25008956fcdc548a3079b096ef96c928
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • RtlInitAnsiString
    • wcstombs
    • ZwOpenKey
    • ZwSetValueKey
    • ZwDeleteKey
    • RtlFormatCurrentUserKeyPath
    • ZwEnumerateKey
    • ZwEnumerateValueKey
    • ZwCreateFile
    • KeWaitForSingleObject
    • IofCallDriver
    • IoBuildSynchronousFsdRequest
    • KeInitializeEvent
    • ObfDereferenceObject
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ZwReadFile
    • ZwWriteFile
    • ZwSetInformationFile
    • ZwOpenProcess
    • ZwTerminateProcess
    • _strupr
    • ZwQuerySystemInformation
    • IoFreeMdl
    • MmUnlockPages
    • MmIsAddressValid
    • MmProbeAndLockPages
    • MmMapLockedPagesSpecifyCache
    • MmBuildMdlForNonPagedPool
    • IoAllocateMdl
    • MmIsNonPagedSystemAddressValid
    • IoGetCurrentProcess
    • PsLookupProcessByProcessId
    • IoDeleteDevice
    • IoDeleteSymbolicLink
    • RtlInitUnicodeString
    • sprintf
    • RtlTimeToTimeFields
    • ExSystemTimeToLocalTime
    • KeQuerySystemTime
    • KeServiceDescriptorTable
    • KeReleaseMutex
    • KeDelayExecutionThread
    • RtlAnsiStringToUnicodeString
    • ExQueueWorkItem
    • KeInsertQueueDpc
    • KeSetTargetProcessorDpc
    • KeInitializeDpc
    • KeNumberProcessors
    • IofCompleteRequest
    • memcpy
    • IoCreateSymbolicLink
    • IoCreateDevice
    • PsCreateSystemThread
    • KeInitializeMutex
    • ObOpenObjectByName
    • IoDriverObjectType
    • ZwOpenDirectoryObject
    • RtlUnicodeStringToAnsiString
    • ZwQueryDirectoryObject
    • DbgPrint
    • IoFileObjectType
    • swprintf
    • IoFreeIrp
    • MmUnmapLockedPages
    • KeSetEvent
    • MmLockPagableSectionByHandle
    • MmLockPagableDataSection
    • IoAllocateIrp
    • _wcsnicmp
    • RtlCompareMemory
    • IoBuildDeviceIoControlRequest
    • _alldiv
    • wcsrchr
    • ZwQueryVolumeInformationFile
    • ZwDeviceIoControlFile
    • _strnicmp
    • ZwFsControlFile
    • _allmul
    • ObfReferenceObject
    • _allrem
    • _stricmp
    • strrchr
    • KeQueryActiveProcessors
    • KeTickCount
    • KeBugCheckEx
    • ZwCreateKey
    • ZwQueryValueKey
    • ExAllocatePoolWithTag
    • ExFreePoolWithTag
    • mbstowcs
    • ZwClose
    • memset
    • PsTerminateSystemThread
    • ZwQueryInformationFile
    • RtlUnwind
    • KeRaiseIrqlToDpcLevel
    • KfRaiseIrql
    • KfLowerIrql
    • KeGetCurrentIrql
    • READ_PORT_ULONG
    • WRITE_PORT_UCHAR
    • READ_PORT_UCHAR
    • READ_PORT_BUFFER_UCHAR
    • KeStallExecutionProcessor

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • NonPaged
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "79a2a585f9d1154213d9b83ef6b68ded",
          "Signature": "1e98aa27b778b508b5c9726db7dfc00e98a635c488c9d2f66df14b1afbd5f92d99009ed1e79b8be13fbd39800c66cd07bc5c9854a694ba10d14e8babf56f65cc6709a2807c52e80e03d66b7ac60518ecc8ac427c072ca73d0866dc00edfd941d73f2729893b111d68fef8eeaacf496510cd08ddf31524f5eaf7da74a75e64ece2b9f292be7cf5d9f037e6e277b23ad622966af92e82ccebd9c7fdccd173c43c2093f7545c79ee4d7607f97c6e4aac769f5fccd74ac2cb048c1504e70561eb535d38ebeb1edacbdfe0cec857dd5bb856644195d9f93eb82ba639ed37c61ffc81bd923587f30a366a139265e92c33ccb3732faf5a38ddcd5b0a3e9253655d781fa",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G3",
          "TBS": {
            "MD5": "e6d820afb23af20a65cf0b03247ea05e",
            "SHA1": "7a8f7c37453f99390ee1e94bb5d3d1cba3a0eea7",
            "SHA256": "7e722dc40e6b9abf8c20aa4d887e34b6d2c6b8cbe53a055d49bf9f5e946e0d27",
            "SHA384": "7e14609969a388d38d227df1dbb9ce086c9a820142c94fd1a28ef2835a8aa528aef4c6399bce344d79adb5f3dad86afa"
          },
          "ValidFrom": "2012-05-01 00:00:00",
          "ValidTo": "2012-12-31 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "47bf1995df8d524643f7db6d480d31a4",
          "Signature": "4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA",
          "TBS": {
            "MD5": "518d2ea8a21e879c942d504824ac211c",
            "SHA1": "21ce87d827077e61abddf2beba69fde5432ea031",
            "SHA256": "1ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7",
            "SHA384": "53e346bbde23779a5d116cc9d86fdd71c97b1f1b343439f8a11aa1d3c87af63864bb8488a5aeb2d0c26a6a1e0b15f03f"
          },
          "ValidFrom": "2003-12-04 00:00:00",
          "ValidTo": "2013-12-03 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "655226e1b22e18e1590f2985ac22e75c",
          "Signature": "8b03c0dd94d841a26169b015a878c730c6903c7e42f724b6e4837317047f04109ca1e2fa812febc0ca44e772e050b6551020836e9692e49a516ab43731dca52deb8c00c71d4fe74d32ba85f84ebefa675565f06abe7aca64381a101078457631f3867a030f60c2b35d9df68b6676821b59e183e5bd49a53856e5de41770e580f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "TBS": {
            "MD5": "650704c342850095f3288eaf791147d4",
            "SHA1": "4cdc38c800761463749c3cbd94a12f32e49877bf",
            "SHA256": "07b8f662558ec85b71b43a79c6e94698144f4ced2308af21e7ba1e5d461da214",
            "SHA384": "2a271d052213438467d09d60eaa4010c8642fff3eb0070e0cf9969428713c8fdc066b90996d594dd3136f5bd0af5a22a"
          },
          "ValidFrom": "2009-05-21 00:00:00",
          "ValidTo": "2019-05-20 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610c120600000000001b",
          "Signature": "01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority",
          "TBS": {
            "MD5": "53c41bc1164e09e0cd1617a5bf913efd",
            "SHA1": "93c03aac8951d494ecd5696b1c08658541b18727",
            "SHA256": "40bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b",
            "SHA384": "f51d4e75ba638f7314cd59b8d6d45f3b34d35ce6986e9d205cd6f333e8e8d8e9c91f636e6bc84731b6661673f40963d8"
          },
          "ValidFrom": "2006-05-23 17:01:29",
          "ValidTo": "2016-05-23 17:11:29",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "25008956fcdc548a3079b096ef96c928",
          "Signature": "49acd6daead15fe8d7445a98d9c495f32e30c0bfe703acba889230d0e71911d319656ef50b2116f52fafc0e98010c27d23c59fc85bfd5a20c274a171279702f4c34435fe76b9746a39c64fd401aec55d0e1dedb33f6a8a4a35b3e4438ea30563562e3627df7abd77736982bd73966cd56b223a57e8cb3e709c316aa968eb8f9ef84560f0d68dc6e37ae179cca59e1ca21216cd04ac1f0913dbfb2ea258ebce38b3b329b2b9bd4dce4c6b568bebe1323e4622a0678ee5326540fbf0667684c9936eae2d879bb500e7f5684633e203cf5c9fcffad04ed7c712678d4209f32f280c1bf91b228a1d88a43f2b9cc0f68109b0ee81f935a87bfef1cf309fa7093a9c51",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=IT, ST=Padova, L=Rubano, O=TG Soft S.a.s. Di Tonello Gianfranco e C., OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=TG Soft S.a.s. Di Tonello Gianfranco e C.",
          "TBS": {
            "MD5": "3bab1e250b6b9f2257ee7e262dfbcb65",
            "SHA1": "f99ffe487f507ecaa1874aedf700f26529baed68",
            "SHA256": "7273308094902ec5a0f89bcd6b8c487363c60ce6527c419dfa163e7f47c2f09d",
            "SHA384": "55f33ea190b96f03dc48a54984dc6889f3b365e5f34e4bb80f4303ff60c8ad231226c5d45649a6091cbd96dfe735ad3a"
          },
          "ValidFrom": "2010-01-15 00:00:00",
          "ValidTo": "2013-01-26 23:59:59",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "SerialNumber": "25008956fcdc548a3079b096ef96c928",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filenameviragt.sys
    Creation Timestamp2016-09-07 02:16:07
    MD508e06b839499cb4b752347399db41b57
    SHA1b53c360b35174bd89f97f681bf7c17f40e519eb6
    SHA256ef6d3c00f9d0aa31a218094480299ef73fc85146adf62fd0c2f4f88972c5c850
    Authentihash MD5d1d42d44e5fcfd9c0a148b0d85f911d0
    Authentihash SHA1eb2d192b58a979cdb127fb81049ff19b07dbe45e
    Authentihash SHA256b59ad4a1f71f8379c89fc3bc1d2827b0785bbb0192b43549034f24a133eea3a5
    RichPEHeaderHash MD5fd47e50698bf05f04850340b52ac1853
    RichPEHeaderHash SHA1ee25f84fd5c60f82580743dfaab31e2e5e1fbe30
    RichPEHeaderHash SHA25644490b82f96dcb06373c259b6532d209604916c484dccba49970a77732bd9906
    CompanyTG Soft S.a.s.
    DescriptionVirIT Agent System
    ProductVirIT Agent System
    OriginalFilenameviragt.sys

    Download

    Certificates

    Expand
    Certificate 7e93ebfb7cc64e59ea4b9a77d406fc3b
    FieldValue
    ToBeSigned (TBS) MD5d0785ad36e427c92b19f6826ab1e8020
    ToBeSigned (TBS) SHA1365b7a9c21bd9373e49052c3e7b3e4646ddd4d43
    ToBeSigned (TBS) SHA256c2abb7484da91a658548de089d52436175fdb760a1387d225611dc0613a1e2ff
    SubjectC=US, O=Symantec Corporation, CN=Symantec Time Stamping Services CA , G2
    ValidFrom2012-12-21 00:00:00
    ValidTo2020-12-30 23:59:59
    Signature03099b8f79ef7f5930aaef68b5fae3091dbb4f82065d375fa6529f168dea1c9209446ef56deb587c30e8f9698d23730b126f47a9ae3911f82ab19bb01ac38eeb599600adce0c4db2d031a6085c2a7afce27a1d574ca86518e979406225966ec7c7376a8321088e41eaddd9573f1d7749872a16065ea6386a2212a35119837eb6
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber7e93ebfb7cc64e59ea4b9a77d406fc3b
    Version3
    Certificate 0ecff438c8febf356e04d86a981b1a50
    FieldValue
    ToBeSigned (TBS) MD5e9d38360b914c8863f6cba3ee58764d3
    ToBeSigned (TBS) SHA14cba8eae47b6bf76f20b3504b98b8f062694a89b
    ToBeSigned (TBS) SHA25688901d86a4cc1f1bb193d08e1fb63d27452e63f83e228c657ab1a92e4ade3976
    SubjectC=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G4
    ValidFrom2012-10-18 00:00:00
    ValidTo2020-12-29 23:59:59
    Signature783bb4912a004cf08f62303778a38427076f18b2de25dca0d49403aa864e259f9a40031cddcee379cb216806dab632b46dbff42c266333e449646d0de6c3670ef705a4356c7c8916c6e9b2dfb2e9dd20c6710fcd9574dcb65cdebd371f4378e678b5cd280420a3aaf14bc48829910e80d111fcdd5c766e4f5e0e4546416e0db0ea389ab13ada097110fc1c79b4807bac69f4fd9cb60c162bf17f5b093d9b5be216ca13816d002e380da8298f2ce1b2f45aa901af159c2c2f491bdb22bbc3fe789451c386b182885df03db451a179332b2e7bb9dc20091371eb6a195bcfe8a530572c89493fb9cf7fc9bf3e226863539abd6974acc51d3c7f92e0c3bc1cd80475
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber0ecff438c8febf356e04d86a981b1a50
    Version3
    Certificate 250ce8e030612e9f2b89f7054d7cf8fd
    FieldValue
    ToBeSigned (TBS) MD5918d9eb6a6cd36c531eceb926170a7e1
    ToBeSigned (TBS) SHA10ae95700d65e6f59715aa47048993ca7858e676a
    ToBeSigned (TBS) SHA25647c46e6eaa3780eace3d0d891346cd373359d246b21a957219dbab4c8f37c166
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. , For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority , G5
    ValidFrom2006-11-08 00:00:00
    ValidTo2021-11-07 23:59:59
    Signature1302ddf8e88600f25af8f8200c59886207cecef74ef9bb59a198e5e138dd4ebc6618d3adeb18f20dc96d3e4a9420c33cbabd6554c6af44b310ad2c6b3eabd707b6b88163c5f95e2ee52a67cecd330c2ad7895603231fb3bee83a0859b4ec4535f78a5bff66cf50afc66d578d1978b7b9a2d157ea1f9a4bafbac98e127ec6bdff
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber250ce8e030612e9f2b89f7054d7cf8fd
    Version3
    Certificate 610c120600000000001b
    FieldValue
    ToBeSigned (TBS) MD553c41bc1164e09e0cd1617a5bf913efd
    ToBeSigned (TBS) SHA193c03aac8951d494ecd5696b1c08658541b18727
    ToBeSigned (TBS) SHA25640bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b
    SubjectC=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
    ValidFrom2006-05-23 17:01:29
    ValidTo2016-05-23 17:11:29
    Signature01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber610c120600000000001b
    Version3
    Certificate 7380a219373c43f82746ddf3ed55eaea
    FieldValue
    ToBeSigned (TBS) MD57ce1cf724ff7a2f7a8a062ec56732b01
    ToBeSigned (TBS) SHA1744e935b56e4974671931f3cbf233d10e95f63bc
    ToBeSigned (TBS) SHA256f091c42ab9e8f450b435dfb1e09109137a0b578737cd49d1f5a1259b5ed44d8c
    SubjectC=IT, ST=Padova, L=Rubano, O=TG Soft S.a.s. Di Tonello Gianfranco e C., CN=TG Soft S.a.s. Di Tonello Gianfranco e C.
    ValidFrom2016-01-20 00:00:00
    ValidTo2019-03-11 23:59:59
    Signature629f1e9a0f9ce5d38b9d6a8dd11af5b17d415d1891039677a3bc1ead43fdf569a403413d461fcfd48f76688244a7a7115e5408682f43319e9526d6dce0fd8ec4a0599331dc94ed2bb68aca4d58e63472587d17cea864ff3cf9ce209f122d904dfafb0db7cab4648b5b903922150f153a527764236b0222d9c1d51ff9631b87fba8b7b079b2ec5839af1be2c721dcebfa5dba429157f785d3a4929c785422ea5d2dacdc68dd1b3ca98c81aba0d7e232fefa7065e861fe51480983ed865dad87663c3a8c505c047ac1b6983917657497403bd7d0df0c71860aa2bec36b1954b1d2dc987e20e71c193f1e59a627c8d6a345b8f7e9b21f0841636672190217727209
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber7380a219373c43f82746ddf3ed55eaea
    Version3
    Certificate 5200e5aa2556fc1a86ed96c9d44b33c7
    FieldValue
    ToBeSigned (TBS) MD5b30c31a572b0409383ed3fbe17e56e81
    ToBeSigned (TBS) SHA14843a82ed3b1f2bfbee9671960e1940c942f688d
    ToBeSigned (TBS) SHA25603cda47a6e654ed85d932714fc09ce4874600eda29ec6628cfbaeb155cab78c9
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 Code Signing 2010 CA
    ValidFrom2010-02-08 00:00:00
    ValidTo2020-02-07 23:59:59
    Signature5622e634a4c461cb48b901ad56a8640fd98c91c4bbcc0ce5ad7aa0227fdf47384a2d6cd17f711a7cec70a9b1f04fe40f0c53fa155efe749849248581261c911447b04c638cbba134d4c645e80d85267303d0a98c646ddc7192e645056015595139fc58146bfed4a4ed796b080c4172e737220609be23e93f449a1ee9619dccb1905cfc3dd28dac423d6536d4b43d40288f9b10cf2326cc4b20cb901f5d8c4c34ca3cd8e537d66fa520bd34eb26d9ae0de7c59af7a1b42191336f86e858bb257c740e58fe751b633fce317c9b8f1b969ec55376845b9cad91faaced93ba5dc82153c2825363af120d5087111b3d5452968a2c9c3d921a089a052ec793a54891d3
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber5200e5aa2556fc1a86ed96c9d44b33c7
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • RtlInitAnsiString
    • wcstombs
    • ZwOpenKey
    • ZwSetValueKey
    • ZwDeleteKey
    • RtlFormatCurrentUserKeyPath
    • ZwEnumerateKey
    • ZwEnumerateValueKey
    • ZwCreateFile
    • KeWaitForSingleObject
    • IofCallDriver
    • IoBuildSynchronousFsdRequest
    • KeInitializeEvent
    • ObfDereferenceObject
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ZwReadFile
    • ZwWriteFile
    • ZwSetInformationFile
    • ZwOpenProcess
    • ZwTerminateProcess
    • _strupr
    • ZwQuerySystemInformation
    • IoFreeMdl
    • MmUnlockPages
    • MmIsAddressValid
    • MmProbeAndLockPages
    • MmMapLockedPagesSpecifyCache
    • MmBuildMdlForNonPagedPool
    • IoAllocateMdl
    • MmIsNonPagedSystemAddressValid
    • IoGetCurrentProcess
    • PsLookupProcessByProcessId
    • IoDeleteDevice
    • IoDeleteSymbolicLink
    • RtlInitUnicodeString
    • sprintf
    • RtlTimeToTimeFields
    • ExSystemTimeToLocalTime
    • KeQuerySystemTime
    • strstr
    • KeServiceDescriptorTable
    • KeReleaseMutex
    • KeDelayExecutionThread
    • RtlAnsiStringToUnicodeString
    • ExQueueWorkItem
    • KeInsertQueueDpc
    • KeSetTargetProcessorDpc
    • KeInitializeDpc
    • KeNumberProcessors
    • IofCompleteRequest
    • PsCreateSystemThread
    • memcpy
    • IoCreateSymbolicLink
    • IoCreateDevice
    • KeInitializeMutex
    • RtlUnicodeStringToAnsiString
    • IoGetDeviceObjectPointer
    • ObOpenObjectByName
    • IoDriverObjectType
    • ZwOpenDirectoryObject
    • ZwQueryDirectoryObject
    • IoFileObjectType
    • swprintf
    • DbgPrint
    • IoFreeIrp
    • MmUnmapLockedPages
    • KeSetEvent
    • MmLockPagableSectionByHandle
    • MmLockPagableDataSection
    • IoAllocateIrp
    • _wcsnicmp
    • RtlCompareMemory
    • IoBuildDeviceIoControlRequest
    • _alldiv
    • wcsrchr
    • ZwQueryVolumeInformationFile
    • ZwDeviceIoControlFile
    • _strnicmp
    • ZwFsControlFile
    • _allmul
    • ObfReferenceObject
    • _allrem
    • _stricmp
    • strrchr
    • KeQueryActiveProcessors
    • KeTickCount
    • KeBugCheckEx
    • ZwCreateKey
    • ZwQueryValueKey
    • ExAllocatePoolWithTag
    • ExFreePoolWithTag
    • mbstowcs
    • ZwClose
    • memset
    • PsTerminateSystemThread
    • ZwQueryInformationFile
    • RtlUnwind
    • KeRaiseIrqlToDpcLevel
    • KfRaiseIrql
    • KfLowerIrql
    • KeGetCurrentIrql
    • READ_PORT_ULONG
    • WRITE_PORT_UCHAR
    • READ_PORT_UCHAR
    • READ_PORT_BUFFER_UCHAR
    • KeStallExecutionProcessor

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • NonPaged
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "79a2a585f9d1154213d9b83ef6b68ded",
          "Signature": "1e98aa27b778b508b5c9726db7dfc00e98a635c488c9d2f66df14b1afbd5f92d99009ed1e79b8be13fbd39800c66cd07bc5c9854a694ba10d14e8babf56f65cc6709a2807c52e80e03d66b7ac60518ecc8ac427c072ca73d0866dc00edfd941d73f2729893b111d68fef8eeaacf496510cd08ddf31524f5eaf7da74a75e64ece2b9f292be7cf5d9f037e6e277b23ad622966af92e82ccebd9c7fdccd173c43c2093f7545c79ee4d7607f97c6e4aac769f5fccd74ac2cb048c1504e70561eb535d38ebeb1edacbdfe0cec857dd5bb856644195d9f93eb82ba639ed37c61ffc81bd923587f30a366a139265e92c33ccb3732faf5a38ddcd5b0a3e9253655d781fa",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G3",
          "TBS": {
            "MD5": "e6d820afb23af20a65cf0b03247ea05e",
            "SHA1": "7a8f7c37453f99390ee1e94bb5d3d1cba3a0eea7",
            "SHA256": "7e722dc40e6b9abf8c20aa4d887e34b6d2c6b8cbe53a055d49bf9f5e946e0d27",
            "SHA384": "7e14609969a388d38d227df1dbb9ce086c9a820142c94fd1a28ef2835a8aa528aef4c6399bce344d79adb5f3dad86afa"
          },
          "ValidFrom": "2012-05-01 00:00:00",
          "ValidTo": "2012-12-31 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "47bf1995df8d524643f7db6d480d31a4",
          "Signature": "4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA",
          "TBS": {
            "MD5": "518d2ea8a21e879c942d504824ac211c",
            "SHA1": "21ce87d827077e61abddf2beba69fde5432ea031",
            "SHA256": "1ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7",
            "SHA384": "53e346bbde23779a5d116cc9d86fdd71c97b1f1b343439f8a11aa1d3c87af63864bb8488a5aeb2d0c26a6a1e0b15f03f"
          },
          "ValidFrom": "2003-12-04 00:00:00",
          "ValidTo": "2013-12-03 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "655226e1b22e18e1590f2985ac22e75c",
          "Signature": "8b03c0dd94d841a26169b015a878c730c6903c7e42f724b6e4837317047f04109ca1e2fa812febc0ca44e772e050b6551020836e9692e49a516ab43731dca52deb8c00c71d4fe74d32ba85f84ebefa675565f06abe7aca64381a101078457631f3867a030f60c2b35d9df68b6676821b59e183e5bd49a53856e5de41770e580f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "TBS": {
            "MD5": "650704c342850095f3288eaf791147d4",
            "SHA1": "4cdc38c800761463749c3cbd94a12f32e49877bf",
            "SHA256": "07b8f662558ec85b71b43a79c6e94698144f4ced2308af21e7ba1e5d461da214",
            "SHA384": "2a271d052213438467d09d60eaa4010c8642fff3eb0070e0cf9969428713c8fdc066b90996d594dd3136f5bd0af5a22a"
          },
          "ValidFrom": "2009-05-21 00:00:00",
          "ValidTo": "2019-05-20 23:59:59",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610c120600000000001b",
          "Signature": "01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority",
          "TBS": {
            "MD5": "53c41bc1164e09e0cd1617a5bf913efd",
            "SHA1": "93c03aac8951d494ecd5696b1c08658541b18727",
            "SHA256": "40bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b",
            "SHA384": "f51d4e75ba638f7314cd59b8d6d45f3b34d35ce6986e9d205cd6f333e8e8d8e9c91f636e6bc84731b6661673f40963d8"
          },
          "ValidFrom": "2006-05-23 17:01:29",
          "ValidTo": "2016-05-23 17:11:29",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "25008956fcdc548a3079b096ef96c928",
          "Signature": "49acd6daead15fe8d7445a98d9c495f32e30c0bfe703acba889230d0e71911d319656ef50b2116f52fafc0e98010c27d23c59fc85bfd5a20c274a171279702f4c34435fe76b9746a39c64fd401aec55d0e1dedb33f6a8a4a35b3e4438ea30563562e3627df7abd77736982bd73966cd56b223a57e8cb3e709c316aa968eb8f9ef84560f0d68dc6e37ae179cca59e1ca21216cd04ac1f0913dbfb2ea258ebce38b3b329b2b9bd4dce4c6b568bebe1323e4622a0678ee5326540fbf0667684c9936eae2d879bb500e7f5684633e203cf5c9fcffad04ed7c712678d4209f32f280c1bf91b228a1d88a43f2b9cc0f68109b0ee81f935a87bfef1cf309fa7093a9c51",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=IT, ST=Padova, L=Rubano, O=TG Soft S.a.s. Di Tonello Gianfranco e C., OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=TG Soft S.a.s. Di Tonello Gianfranco e C.",
          "TBS": {
            "MD5": "3bab1e250b6b9f2257ee7e262dfbcb65",
            "SHA1": "f99ffe487f507ecaa1874aedf700f26529baed68",
            "SHA256": "7273308094902ec5a0f89bcd6b8c487363c60ce6527c419dfa163e7f47c2f09d",
            "SHA384": "55f33ea190b96f03dc48a54984dc6889f3b365e5f34e4bb80f4303ff60c8ad231226c5d45649a6091cbd96dfe735ad3a"
          },
          "ValidFrom": "2010-01-15 00:00:00",
          "ValidTo": "2013-01-26 23:59:59",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "SerialNumber": "25008956fcdc548a3079b096ef96c928",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    source

    last_updated: 2024-09-26