9454a752-233e-4ba2-b585-8da242bf8f31

Netfilter.sys :inline

Description

Confirmed vulnerable driver from Microsoft Block List

  • UUID: 9454a752-233e-4ba2-b585-8da242bf8f31
  • Created: 2023-07-22
  • Author: Michael Haag
  • Acknowledgement: |

DownloadBlock

Use CasePrivilegesOperating System
Elevate privilegeskernelWindows

Detections

YARA 🏹

Expand

Sigma 🛡️

Expand

Names

detects loading using name only

Hashes

detects loading using hashes only

Sysmon 🔎

Expand

Block

on hashes

Alert

on hashes

Resources


  • https://gist.github.com/mgraeber-rc/1bde6a2a83237f17b463d051d32e802c

  • CVE

  • Known Vulnerable Samples

    PropertyValue
    Filename
    Creation Timestamp2021-05-09 05:38:33
    MD51e9f5515bff6f29d06694be4cd95a21c
    SHA1919b22b086fb2718648e61274e7ae9535efa9a99
    SHA25622da5a055b7b17c69def9f5af54e257c751507e7b6b9a835fcf6245ab90ae750
    Authentihash MD5d28a2c907981a32d7855fbf5e8e61c48
    Authentihash SHA105ac1c64ca16ab0517fe85d4499d08199e63df26
    Authentihash SHA256b430d3a0bdb837a5d6625d3b1cef07abd1953f969869ff6cf7ba398ae605431a
    RichPEHeaderHash MD5f0b684c190bdbac4aa311a7355122963
    RichPEHeaderHash SHA1b7866474ab0a322b84086fccf1948d5a8b7f03a0
    RichPEHeaderHash SHA25633c5dfb8ba99a1d23f6a99cb34c04977b2455fa6c59e79dbad4d910516357bae

    Download

    Certificates

    Expand
    Certificate 33000000b5213fca1e4aa03de40000000000b5
    FieldValue
    ToBeSigned (TBS) MD5a0dd89c33c4973bf6758331e200fb6de
    ToBeSigned (TBS) SHA165ff7fa429c0f08f8a8bf30509e8ca2919d9edb5
    ToBeSigned (TBS) SHA25629a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher
    ValidFrom2020-12-15 22:15:33
    ValidTo2021-12-02 22:15:33
    Signature0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber33000000b5213fca1e4aa03de40000000000b5
    Version3
    Certificate 610baac1000000000009
    FieldValue
    ToBeSigned (TBS) MD5a569061297e8e824767dbc3184a69bea
    ToBeSigned (TBS) SHA1adbb26a587a8f44b4fccaecb306f980d1c55a150
    ToBeSigned (TBS) SHA256cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012
    ValidFrom2012-04-18 23:48:38
    ValidTo2027-04-18 23:58:38
    Signature5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber610baac1000000000009
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • ntoskrnl.exe
    • NETIO.SYS
    • HAL.dll
    • WDFLDR.SYS

    Imported Functions

    Expand
    • FwpsAcquireClassifyHandle0
    • FwpsReleaseClassifyHandle0
    • FwpmFilterDeleteById0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpmFilterAdd0
    • FwpmCalloutAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmTransactionAbort0
    • FwpmTransactionCommit0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpsCalloutUnregisterById0
    • FwpsCompleteClassify0
    • FwpsCalloutRegister1
    • IofCallDriver
    • IoCreateFile
    • IoFreeIrp
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwQueryInformationFile
    • ZwSetInformationFile
    • ZwReadFile
    • ZwWriteFile
    • ZwClose
    • IoFileObjectType
    • KeEnterCriticalRegion
    • KeLeaveCriticalRegion
    • PsTerminateSystemThread
    • KeSetBasePriorityThread
    • sprintf
    • CmUnRegisterCallback
    • CmRegisterCallbackEx
    • CmCallbackGetKeyObjectID
    • MmIsAddressValid
    • strlen
    • strncmp
    • strncpy
    • wcscat
    • wcslen
    • wcsncmp
    • RtlInitAnsiString
    • strcat
    • strcmp
    • strncat
    • ExAllocatePoolWithTag
    • ExAcquireSpinLockExclusive
    • ExReleaseSpinLockExclusive
    • wcscpy
    • RtlAnsiStringToUnicodeString
    • RtlFreeUnicodeString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeResetEvent
    • KeInitializeTimerEx
    • KeSetTimerEx
    • PsCreateSystemThread
    • ZwCreateKey
    • ZwOpenKey
    • ZwFlushKey
    • ZwQueryValueKey
    • ZwSetValueKey
    • NtQueryInformationToken
    • RtlLengthSid
    • RtlConvertSidToUnicodeString
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlSetOwnerSecurityDescriptor
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwOpenProcessTokenEx
    • ZwSetSecurityObject
    • PsGetProcessImageFileName
    • _allmul
    • PsProcessType
    • SeExports
    • strchr
    • strncpy_s
    • MmProbeAndLockPages
    • MmUnlockPages
    • IoAllocateMdl
    • IoFreeMdl
    • IoReuseIrp
    • IoAllocateIrp
    • RtlUnwind
    • KeWaitForSingleObject
    • KeSetEvent
    • KeInitializeEvent
    • KeGetCurrentThread
    • IoDeleteSymbolicLink
    • KeBugCheckEx
    • ExFreePoolWithTag
    • RtlInitUnicodeString
    • RtlCopyUnicodeString
    • strcpy
    • memset
    • memcpy
    • strstr
    • WskDeregister
    • WskReleaseProviderNPI
    • WskCaptureProviderNPI
    • WskRegister
    • KeGetCurrentIrql
    • WdfVersionBind
    • WdfVersionBindClass
    • WdfVersionUnbindClass
    • WdfVersionUnbind

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Signature": "0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
          "TBS": {
            "MD5": "a0dd89c33c4973bf6758331e200fb6de",
            "SHA1": "65ff7fa429c0f08f8a8bf30509e8ca2919d9edb5",
            "SHA256": "29a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47",
            "SHA384": "a7ac729302762483ea304ff2660a2ce2f5fa67cbbfc3f6df32a8feafa3852812c9bb8f7050140079aad1dec8119ee88e"
          },
          "ValidFrom": "2020-12-15 22:15:33",
          "ValidTo": "2021-12-02 22:15:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610baac1000000000009",
          "Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "TBS": {
            "MD5": "a569061297e8e824767dbc3184a69bea",
            "SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
            "SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
            "SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
          },
          "ValidFrom": "2012-04-18 23:48:38",
          "ValidTo": "2027-04-18 23:58:38",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2021-05-15 06:44:55
    MD54fbf95520d372ed081a16e1ccfb3c154
    SHA145f68dd09d129264abed173fcdd5c56e1147a977
    SHA25623115b5b1d5511d59cdad75f863d65893304dc098848dcb149b69492f51b31f6
    Authentihash MD55064073c3f84f1569377081c4ad33867
    Authentihash SHA1aca8e53483b40a06dfdee81bb364b1622f9156fe
    Authentihash SHA2563d31118a2e92377ecb632bd722132c04af4e65e24ff87743796c75eb07cfcd71
    RichPEHeaderHash MD5f0b684c190bdbac4aa311a7355122963
    RichPEHeaderHash SHA1b7866474ab0a322b84086fccf1948d5a8b7f03a0
    RichPEHeaderHash SHA25633c5dfb8ba99a1d23f6a99cb34c04977b2455fa6c59e79dbad4d910516357bae

    Download

    Imports

    Expand
    • fwpkclnt.sys
    • ntoskrnl.exe
    • NETIO.SYS
    • HAL.dll
    • WDFLDR.SYS

    Imported Functions

    Expand
    • FwpsAcquireClassifyHandle0
    • FwpsReleaseClassifyHandle0
    • FwpmFilterDeleteById0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpmFilterAdd0
    • FwpmCalloutAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmTransactionAbort0
    • FwpmTransactionCommit0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpsCalloutUnregisterById0
    • FwpsCompleteClassify0
    • FwpsCalloutRegister1
    • IofCallDriver
    • IoCreateFile
    • IoFreeIrp
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwQueryInformationFile
    • ZwSetInformationFile
    • ZwReadFile
    • ZwWriteFile
    • ZwClose
    • IoFileObjectType
    • KeEnterCriticalRegion
    • KeLeaveCriticalRegion
    • PsTerminateSystemThread
    • KeSetBasePriorityThread
    • sprintf
    • CmUnRegisterCallback
    • CmRegisterCallbackEx
    • CmCallbackGetKeyObjectID
    • MmIsAddressValid
    • strlen
    • strncmp
    • strncpy
    • wcscat
    • wcslen
    • wcsncmp
    • RtlInitAnsiString
    • strcat
    • strcmp
    • strncat
    • ExAllocatePoolWithTag
    • ExAcquireSpinLockExclusive
    • ExReleaseSpinLockExclusive
    • wcscpy
    • RtlAnsiStringToUnicodeString
    • RtlFreeUnicodeString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeResetEvent
    • KeInitializeTimerEx
    • KeSetTimerEx
    • PsCreateSystemThread
    • ZwCreateKey
    • ZwOpenKey
    • ZwFlushKey
    • ZwQueryValueKey
    • ZwSetValueKey
    • NtQueryInformationToken
    • RtlLengthSid
    • RtlConvertSidToUnicodeString
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlSetOwnerSecurityDescriptor
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwOpenProcessTokenEx
    • ZwSetSecurityObject
    • PsGetProcessImageFileName
    • _allmul
    • PsProcessType
    • SeExports
    • strchr
    • strncpy_s
    • MmProbeAndLockPages
    • MmUnlockPages
    • IoAllocateMdl
    • IoFreeMdl
    • IoReuseIrp
    • IoAllocateIrp
    • RtlUnwind
    • KeWaitForSingleObject
    • KeSetEvent
    • KeInitializeEvent
    • KeGetCurrentThread
    • IoDeleteSymbolicLink
    • KeBugCheckEx
    • ExFreePoolWithTag
    • RtlInitUnicodeString
    • RtlCopyUnicodeString
    • strcpy
    • memset
    • memcpy
    • strstr
    • WskDeregister
    • WskReleaseProviderNPI
    • WskCaptureProviderNPI
    • WskRegister
    • KeGetCurrentIrql
    • WdfVersionBind
    • WdfVersionBindClass
    • WdfVersionUnbindClass
    • WdfVersionUnbind

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Signature": "0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
          "TBS": {
            "MD5": "a0dd89c33c4973bf6758331e200fb6de",
            "SHA1": "65ff7fa429c0f08f8a8bf30509e8ca2919d9edb5",
            "SHA256": "29a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47",
            "SHA384": "a7ac729302762483ea304ff2660a2ce2f5fa67cbbfc3f6df32a8feafa3852812c9bb8f7050140079aad1dec8119ee88e"
          },
          "ValidFrom": "2020-12-15 22:15:33",
          "ValidTo": "2021-12-02 22:15:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610baac1000000000009",
          "Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "TBS": {
            "MD5": "a569061297e8e824767dbc3184a69bea",
            "SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
            "SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
            "SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
          },
          "ValidFrom": "2012-04-18 23:48:38",
          "ValidTo": "2027-04-18 23:58:38",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2021-05-14 20:22:09
    MD546e5dfe28aeccc39ea893975d54e3d3b
    SHA10df5e8599b332a7927bd0a9d87ad9d6b5ad332fe
    SHA256f3efcf47681d9f96afcbc843a241c21a643b173c48270446f6fe634991a57847
    Authentihash MD513e6bd0963191685d86aa909a5769b3f
    Authentihash SHA13c20bb896fd16b5c698185fb176e820a448997b3
    Authentihash SHA256cc383ad11e9d06047a1558ed343f389492da3ac2b84b71462aee502a2fa616c8
    RichPEHeaderHash MD56f68a8d35e578addef21fc78e0db33a2
    RichPEHeaderHash SHA1a033bd7a041b2df1f345fca32d98a86c0e4a56b6
    RichPEHeaderHash SHA256aaf6113599fa8837e1427737348e2c76b05a63fe85b5fbc5de8661d5e1f03cbe

    Download

    Certificates

    Expand
    Certificate 33000000b5213fca1e4aa03de40000000000b5
    FieldValue
    ToBeSigned (TBS) MD5a0dd89c33c4973bf6758331e200fb6de
    ToBeSigned (TBS) SHA165ff7fa429c0f08f8a8bf30509e8ca2919d9edb5
    ToBeSigned (TBS) SHA25629a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher
    ValidFrom2020-12-15 22:15:33
    ValidTo2021-12-02 22:15:33
    Signature0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber33000000b5213fca1e4aa03de40000000000b5
    Version3
    Certificate 610baac1000000000009
    FieldValue
    ToBeSigned (TBS) MD5a569061297e8e824767dbc3184a69bea
    ToBeSigned (TBS) SHA1adbb26a587a8f44b4fccaecb306f980d1c55a150
    ToBeSigned (TBS) SHA256cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012
    ValidFrom2012-04-18 23:48:38
    ValidTo2027-04-18 23:58:38
    Signature5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber610baac1000000000009
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • WDFLDR.SYS

    Imported Functions

    Expand
    • RtlInitUnicodeString
    • IoDeleteSymbolicLink
    • RtlCopyUnicodeString
    • WdfVersionUnbindClass
    • WdfVersionBindClass
    • WdfVersionBind
    • WdfVersionUnbind

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Signature": "0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
          "TBS": {
            "MD5": "a0dd89c33c4973bf6758331e200fb6de",
            "SHA1": "65ff7fa429c0f08f8a8bf30509e8ca2919d9edb5",
            "SHA256": "29a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47",
            "SHA384": "a7ac729302762483ea304ff2660a2ce2f5fa67cbbfc3f6df32a8feafa3852812c9bb8f7050140079aad1dec8119ee88e"
          },
          "ValidFrom": "2020-12-15 22:15:33",
          "ValidTo": "2021-12-02 22:15:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610baac1000000000009",
          "Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "TBS": {
            "MD5": "a569061297e8e824767dbc3184a69bea",
            "SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
            "SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
            "SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
          },
          "ValidFrom": "2012-04-18 23:48:38",
          "ValidTo": "2027-04-18 23:58:38",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2021-05-15 06:46:21
    MD5a01abca106a37eb4e7f96b1c4be38712
    SHA10f45c274b86bdcffba8d09a3cdfce974b10e3bfe
    SHA256cfe2dd2cf1eb8b79d3b4ae980cda6fd933979d47c837fda77256a24a41316468
    Authentihash MD58c667904b9db9e69a637c55ae50decbd
    Authentihash SHA1bc2f3850c7b858340d7ed27b90e63b036881fd6c
    Authentihash SHA256f08ebddc11aefcb46082c239f8d97ceea247d846e22c4bcdd72af75c1cbc6b0b
    RichPEHeaderHash MD5f0b684c190bdbac4aa311a7355122963
    RichPEHeaderHash SHA1b7866474ab0a322b84086fccf1948d5a8b7f03a0
    RichPEHeaderHash SHA25633c5dfb8ba99a1d23f6a99cb34c04977b2455fa6c59e79dbad4d910516357bae

    Download

    Imports

    Expand
    • fwpkclnt.sys
    • ntoskrnl.exe
    • NETIO.SYS
    • HAL.dll
    • WDFLDR.SYS

    Imported Functions

    Expand
    • FwpsAcquireClassifyHandle0
    • FwpsReleaseClassifyHandle0
    • FwpmFilterDeleteById0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpmFilterAdd0
    • FwpmCalloutAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmTransactionAbort0
    • FwpmTransactionCommit0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpsCalloutUnregisterById0
    • FwpsCompleteClassify0
    • FwpsCalloutRegister1
    • IofCallDriver
    • IoCreateFile
    • IoFreeIrp
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwQueryInformationFile
    • ZwSetInformationFile
    • ZwReadFile
    • ZwWriteFile
    • ZwClose
    • IoFileObjectType
    • KeEnterCriticalRegion
    • KeLeaveCriticalRegion
    • PsTerminateSystemThread
    • KeSetBasePriorityThread
    • sprintf
    • CmUnRegisterCallback
    • CmRegisterCallbackEx
    • CmCallbackGetKeyObjectID
    • MmIsAddressValid
    • strlen
    • strncmp
    • strncpy
    • wcscat
    • wcslen
    • wcsncmp
    • RtlInitAnsiString
    • strcat
    • strcmp
    • strncat
    • ExAllocatePoolWithTag
    • ExAcquireSpinLockExclusive
    • ExReleaseSpinLockExclusive
    • wcscpy
    • RtlAnsiStringToUnicodeString
    • RtlFreeUnicodeString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeResetEvent
    • KeInitializeTimerEx
    • KeSetTimerEx
    • PsCreateSystemThread
    • ZwCreateKey
    • ZwOpenKey
    • ZwFlushKey
    • ZwQueryValueKey
    • ZwSetValueKey
    • NtQueryInformationToken
    • RtlLengthSid
    • RtlConvertSidToUnicodeString
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlSetOwnerSecurityDescriptor
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwOpenProcessTokenEx
    • ZwSetSecurityObject
    • PsGetProcessImageFileName
    • _allmul
    • PsProcessType
    • SeExports
    • strchr
    • strncpy_s
    • MmProbeAndLockPages
    • MmUnlockPages
    • IoAllocateMdl
    • IoFreeMdl
    • IoReuseIrp
    • IoAllocateIrp
    • RtlUnwind
    • KeWaitForSingleObject
    • KeSetEvent
    • KeInitializeEvent
    • KeGetCurrentThread
    • IoDeleteSymbolicLink
    • KeBugCheckEx
    • ExFreePoolWithTag
    • RtlInitUnicodeString
    • RtlCopyUnicodeString
    • strcpy
    • memset
    • memcpy
    • strstr
    • WskDeregister
    • WskReleaseProviderNPI
    • WskCaptureProviderNPI
    • WskRegister
    • KeGetCurrentIrql
    • WdfVersionBind
    • WdfVersionBindClass
    • WdfVersionUnbindClass
    • WdfVersionUnbind

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Signature": "0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
          "TBS": {
            "MD5": "a0dd89c33c4973bf6758331e200fb6de",
            "SHA1": "65ff7fa429c0f08f8a8bf30509e8ca2919d9edb5",
            "SHA256": "29a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47",
            "SHA384": "a7ac729302762483ea304ff2660a2ce2f5fa67cbbfc3f6df32a8feafa3852812c9bb8f7050140079aad1dec8119ee88e"
          },
          "ValidFrom": "2020-12-15 22:15:33",
          "ValidTo": "2021-12-02 22:15:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610baac1000000000009",
          "Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "TBS": {
            "MD5": "a569061297e8e824767dbc3184a69bea",
            "SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
            "SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
            "SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
          },
          "ValidFrom": "2012-04-18 23:48:38",
          "ValidTo": "2027-04-18 23:58:38",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2021-05-15 06:46:38
    MD5530f12f8058199964d0b41f1856185ec
    SHA18b04023990d18dcd5cc4c5538b332b017f3962fc
    SHA256bbc58fd69ce5fed6691dd8d2084e9b728add808ffd5ea8b42ac284b686f77d9a
    Authentihash MD5086a664c2a188f4a1db40a1684597517
    Authentihash SHA18241c9a5755a740811c8e8d2739b33146acd3e6d
    Authentihash SHA256c56536f99207915e5a1f7d4f014ab942bd820e64ff7f371ad0462ef26ed27242
    RichPEHeaderHash MD585bc198af7e82d3ad73505bc7086be84
    RichPEHeaderHash SHA1e652b262f08c568106765e202ea0142129765004
    RichPEHeaderHash SHA2564130707eedc8cb72f6c5703feee7b8bfbdbe7dc34630d6dc33a0f92da20bdb66

    Download

    Certificates

    Expand
    Certificate 33000000b5213fca1e4aa03de40000000000b5
    FieldValue
    ToBeSigned (TBS) MD5a0dd89c33c4973bf6758331e200fb6de
    ToBeSigned (TBS) SHA165ff7fa429c0f08f8a8bf30509e8ca2919d9edb5
    ToBeSigned (TBS) SHA25629a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher
    ValidFrom2020-12-15 22:15:33
    ValidTo2021-12-02 22:15:33
    Signature0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber33000000b5213fca1e4aa03de40000000000b5
    Version3
    Certificate 610baac1000000000009
    FieldValue
    ToBeSigned (TBS) MD5a569061297e8e824767dbc3184a69bea
    ToBeSigned (TBS) SHA1adbb26a587a8f44b4fccaecb306f980d1c55a150
    ToBeSigned (TBS) SHA256cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012
    ValidFrom2012-04-18 23:48:38
    ValidTo2027-04-18 23:58:38
    Signature5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber610baac1000000000009
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • ntoskrnl.exe
    • NETIO.SYS
    • WDFLDR.SYS

    Imported Functions

    Expand
    • FwpmFilterAdd0
    • FwpmFilterDeleteById0
    • FwpsAcquireClassifyHandle0
    • FwpmCalloutAdd0
    • FwpsCompleteClassify0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmTransactionAbort0
    • FwpmTransactionCommit0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpsCalloutUnregisterById0
    • FwpsReleaseClassifyHandle0
    • FwpsCalloutRegister1
    • IoCreateFile
    • IoFreeIrp
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwQueryInformationFile
    • ZwSetInformationFile
    • ZwReadFile
    • ZwWriteFile
    • ZwClose
    • IoFileObjectType
    • KeEnterCriticalRegion
    • KeLeaveCriticalRegion
    • PsTerminateSystemThread
    • KeSetBasePriorityThread
    • sprintf
    • CmUnRegisterCallback
    • CmRegisterCallbackEx
    • CmCallbackGetKeyObjectID
    • MmIsAddressValid
    • strlen
    • strncmp
    • strncpy
    • wcscat
    • wcslen
    • wcsncmp
    • RtlInitAnsiString
    • strcat
    • strcmp
    • strncat
    • IoAllocateIrp
    • ExAcquireSpinLockExclusive
    • ExReleaseSpinLockExclusive
    • wcscpy
    • RtlAnsiStringToUnicodeString
    • RtlFreeUnicodeString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeResetEvent
    • KeInitializeTimerEx
    • KeSetTimerEx
    • PsCreateSystemThread
    • ZwCreateKey
    • ZwOpenKey
    • ZwFlushKey
    • ZwQueryValueKey
    • ZwSetValueKey
    • NtQueryInformationToken
    • RtlLengthSid
    • RtlConvertSidToUnicodeString
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlSetOwnerSecurityDescriptor
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwOpenProcessTokenEx
    • ZwSetSecurityObject
    • PsGetProcessImageFileName
    • PsProcessType
    • SeExports
    • strchr
    • strncpy_s
    • MmProbeAndLockPages
    • MmUnlockPages
    • IoAllocateMdl
    • IoFreeMdl
    • IoReuseIrp
    • __C_specific_handler
    • IofCallDriver
    • ExAllocatePoolWithTag
    • KeWaitForSingleObject
    • KeSetEvent
    • KeInitializeEvent
    • IoDeleteSymbolicLink
    • KeBugCheckEx
    • RtlCopyUnicodeString
    • ExFreePoolWithTag
    • RtlInitUnicodeString
    • strcpy
    • strstr
    • WskCaptureProviderNPI
    • WskReleaseProviderNPI
    • WskDeregister
    • WskRegister
    • WdfVersionBind
    • WdfVersionBindClass
    • WdfVersionUnbindClass
    • WdfVersionUnbind

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Signature": "0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
          "TBS": {
            "MD5": "a0dd89c33c4973bf6758331e200fb6de",
            "SHA1": "65ff7fa429c0f08f8a8bf30509e8ca2919d9edb5",
            "SHA256": "29a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47",
            "SHA384": "a7ac729302762483ea304ff2660a2ce2f5fa67cbbfc3f6df32a8feafa3852812c9bb8f7050140079aad1dec8119ee88e"
          },
          "ValidFrom": "2020-12-15 22:15:33",
          "ValidTo": "2021-12-02 22:15:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610baac1000000000009",
          "Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "TBS": {
            "MD5": "a569061297e8e824767dbc3184a69bea",
            "SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
            "SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
            "SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
          },
          "ValidFrom": "2012-04-18 23:48:38",
          "ValidTo": "2027-04-18 23:58:38",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2021-05-15 06:46:38
    MD53ce1153adde6ca1fa17679d9f00b4de0
    SHA156086ede8efe41322b829aaec81df6ef317809e7
    SHA25616e68d2fa75a4e04872be42e2b54c041e43ab3409096741690520417e3368aa6
    Authentihash MD5086a664c2a188f4a1db40a1684597517
    Authentihash SHA18241c9a5755a740811c8e8d2739b33146acd3e6d
    Authentihash SHA256c56536f99207915e5a1f7d4f014ab942bd820e64ff7f371ad0462ef26ed27242
    RichPEHeaderHash MD585bc198af7e82d3ad73505bc7086be84
    RichPEHeaderHash SHA1e652b262f08c568106765e202ea0142129765004
    RichPEHeaderHash SHA2564130707eedc8cb72f6c5703feee7b8bfbdbe7dc34630d6dc33a0f92da20bdb66

    Download

    Imports

    Expand
    • fwpkclnt.sys
    • ntoskrnl.exe
    • NETIO.SYS
    • WDFLDR.SYS

    Imported Functions

    Expand
    • FwpmFilterAdd0
    • FwpmFilterDeleteById0
    • FwpsAcquireClassifyHandle0
    • FwpmCalloutAdd0
    • FwpsCompleteClassify0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmTransactionAbort0
    • FwpmTransactionCommit0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpsCalloutUnregisterById0
    • FwpsReleaseClassifyHandle0
    • FwpsCalloutRegister1
    • IoCreateFile
    • IoFreeIrp
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwQueryInformationFile
    • ZwSetInformationFile
    • ZwReadFile
    • ZwWriteFile
    • ZwClose
    • IoFileObjectType
    • KeEnterCriticalRegion
    • KeLeaveCriticalRegion
    • PsTerminateSystemThread
    • KeSetBasePriorityThread
    • sprintf
    • CmUnRegisterCallback
    • CmRegisterCallbackEx
    • CmCallbackGetKeyObjectID
    • MmIsAddressValid
    • strlen
    • strncmp
    • strncpy
    • wcscat
    • wcslen
    • wcsncmp
    • RtlInitAnsiString
    • strcat
    • strcmp
    • strncat
    • IoAllocateIrp
    • ExAcquireSpinLockExclusive
    • ExReleaseSpinLockExclusive
    • wcscpy
    • RtlAnsiStringToUnicodeString
    • RtlFreeUnicodeString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeResetEvent
    • KeInitializeTimerEx
    • KeSetTimerEx
    • PsCreateSystemThread
    • ZwCreateKey
    • ZwOpenKey
    • ZwFlushKey
    • ZwQueryValueKey
    • ZwSetValueKey
    • NtQueryInformationToken
    • RtlLengthSid
    • RtlConvertSidToUnicodeString
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlSetOwnerSecurityDescriptor
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwOpenProcessTokenEx
    • ZwSetSecurityObject
    • PsGetProcessImageFileName
    • PsProcessType
    • SeExports
    • strchr
    • strncpy_s
    • MmProbeAndLockPages
    • MmUnlockPages
    • IoAllocateMdl
    • IoFreeMdl
    • IoReuseIrp
    • __C_specific_handler
    • IofCallDriver
    • ExAllocatePoolWithTag
    • KeWaitForSingleObject
    • KeSetEvent
    • KeInitializeEvent
    • IoDeleteSymbolicLink
    • KeBugCheckEx
    • RtlCopyUnicodeString
    • ExFreePoolWithTag
    • RtlInitUnicodeString
    • strcpy
    • strstr
    • WskCaptureProviderNPI
    • WskReleaseProviderNPI
    • WskDeregister
    • WskRegister
    • WdfVersionBind
    • WdfVersionBindClass
    • WdfVersionUnbindClass
    • WdfVersionUnbind

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Signature": "0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
          "TBS": {
            "MD5": "a0dd89c33c4973bf6758331e200fb6de",
            "SHA1": "65ff7fa429c0f08f8a8bf30509e8ca2919d9edb5",
            "SHA256": "29a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47",
            "SHA384": "a7ac729302762483ea304ff2660a2ce2f5fa67cbbfc3f6df32a8feafa3852812c9bb8f7050140079aad1dec8119ee88e"
          },
          "ValidFrom": "2020-12-15 22:15:33",
          "ValidTo": "2021-12-02 22:15:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610baac1000000000009",
          "Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "TBS": {
            "MD5": "a569061297e8e824767dbc3184a69bea",
            "SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
            "SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
            "SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
          },
          "ValidFrom": "2012-04-18 23:48:38",
          "ValidTo": "2027-04-18 23:58:38",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2021-05-15 01:06:29
    MD52ff65eaca2ace4d13d0c7db521120e51
    SHA1a9c16b188132cdf9e9d02ddda7727a241dc43ce2
    SHA25604a269dd0a03e32e5b2a1c8ab0768791962e040d080d44dc44dab01dd7954f2b
    Authentihash MD5952d13ef24460cf6d9f7ce78005bc918
    Authentihash SHA13debe170b5a113407f9e86ee6ed9ae00c3d82c9f
    Authentihash SHA256221dfbc74bbb255b0879360ccc71a74b756b2e0f16e9386b38a9ce9d4e2e34f9
    RichPEHeaderHash MD54515084119c0d55b8843fcbe64611276
    RichPEHeaderHash SHA178482066a1bb564c20bb2361adb896a05dbaaec9
    RichPEHeaderHash SHA256e78ad40b7b64192da4009a3335caba162323bb5f86e38532eed33957951248b0

    Download

    Certificates

    Expand
    Certificate 33000000b5213fca1e4aa03de40000000000b5
    FieldValue
    ToBeSigned (TBS) MD5a0dd89c33c4973bf6758331e200fb6de
    ToBeSigned (TBS) SHA165ff7fa429c0f08f8a8bf30509e8ca2919d9edb5
    ToBeSigned (TBS) SHA25629a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher
    ValidFrom2020-12-15 22:15:33
    ValidTo2021-12-02 22:15:33
    Signature0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber33000000b5213fca1e4aa03de40000000000b5
    Version3
    Certificate 610baac1000000000009
    FieldValue
    ToBeSigned (TBS) MD5a569061297e8e824767dbc3184a69bea
    ToBeSigned (TBS) SHA1adbb26a587a8f44b4fccaecb306f980d1c55a150
    ToBeSigned (TBS) SHA256cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012
    ValidFrom2012-04-18 23:48:38
    ValidTo2027-04-18 23:58:38
    Signature5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber610baac1000000000009
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • ntoskrnl.exe
    • WDFLDR.SYS

    Imported Functions

    Expand
    • FwpmTransactionCommit0
    • FwpmTransactionAbort0
    • FwpmSubLayerAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmCalloutAdd0
    • FwpmTransactionBegin0
    • FwpmFilterDeleteById0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpsCalloutUnregisterById0
    • FwpmFilterAdd0
    • FwpsCalloutRegister1
    • ExAllocatePoolWithTag
    • ExFreePoolWithTag
    • KeSetEvent
    • KeEnterCriticalRegion
    • KeLeaveCriticalRegion
    • PsTerminateSystemThread
    • KeSetBasePriorityThread
    • KeInitializeTimerEx
    • KeSetTimerEx
    • PsCreateSystemThread
    • ZwCreateKey
    • ZwFlushKey
    • ZwSetValueKey
    • MmIsAddressValid
    • KeWaitForSingleObject
    • KeBugCheckEx
    • RtlCopyUnicodeString
    • KeInitializeEvent
    • IoDeleteSymbolicLink
    • RtlInitUnicodeString
    • ZwClose
    • WdfVersionBind
    • WdfVersionBindClass
    • WdfVersionUnbindClass
    • WdfVersionUnbind

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Signature": "0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
          "TBS": {
            "MD5": "a0dd89c33c4973bf6758331e200fb6de",
            "SHA1": "65ff7fa429c0f08f8a8bf30509e8ca2919d9edb5",
            "SHA256": "29a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47",
            "SHA384": "a7ac729302762483ea304ff2660a2ce2f5fa67cbbfc3f6df32a8feafa3852812c9bb8f7050140079aad1dec8119ee88e"
          },
          "ValidFrom": "2020-12-15 22:15:33",
          "ValidTo": "2021-12-02 22:15:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610baac1000000000009",
          "Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "TBS": {
            "MD5": "a569061297e8e824767dbc3184a69bea",
            "SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
            "SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
            "SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
          },
          "ValidFrom": "2012-04-18 23:48:38",
          "ValidTo": "2027-04-18 23:58:38",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2021-03-27 02:41:44
    MD5e3fb0f73f17f1fe04ae8fa9448d2f92b
    SHA14656f21f4093a72864b12ad6783a640ec9d4adff
    SHA25640c45c9b1c764777096b59f99ae524cbd25b88c805187e615c3ed6840f3d4c15
    Authentihash MD58ed8507c953e60b61f022350417236fa
    Authentihash SHA12c27abbbbcf10dfb75ad79557e30ace5ed314df8
    Authentihash SHA2567f1772bdf7dd81cb00d30159d19d4eb9160b54d7609b36f781d08ca3afbd29a7
    RichPEHeaderHash MD5b324bb3bfe051a8ce6eaa984b648d37e
    RichPEHeaderHash SHA15ca6f0de15e83eadef9ab16f19d18b89fbc171fb
    RichPEHeaderHash SHA256c6eea0ec611fb1f51ab52e0625649f40428c2bcb8865f0b89ca9f1900f6c53f2

    Download

    Certificates

    Expand
    Certificate 33000000b5213fca1e4aa03de40000000000b5
    FieldValue
    ToBeSigned (TBS) MD5a0dd89c33c4973bf6758331e200fb6de
    ToBeSigned (TBS) SHA165ff7fa429c0f08f8a8bf30509e8ca2919d9edb5
    ToBeSigned (TBS) SHA25629a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher
    ValidFrom2020-12-15 22:15:33
    ValidTo2021-12-02 22:15:33
    Signature0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber33000000b5213fca1e4aa03de40000000000b5
    Version3
    Certificate 610baac1000000000009
    FieldValue
    ToBeSigned (TBS) MD5a569061297e8e824767dbc3184a69bea
    ToBeSigned (TBS) SHA1adbb26a587a8f44b4fccaecb306f980d1c55a150
    ToBeSigned (TBS) SHA256cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012
    ValidFrom2012-04-18 23:48:38
    ValidTo2027-04-18 23:58:38
    Signature5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber610baac1000000000009
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • ntoskrnl.exe
    • NETIO.SYS
    • WDFLDR.SYS

    Imported Functions

    Expand
    • FwpmFilterAdd0
    • FwpmFilterDeleteById0
    • FwpsAcquireClassifyHandle0
    • FwpmCalloutAdd0
    • FwpsCompleteClassify0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmTransactionAbort0
    • FwpmTransactionCommit0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpsCalloutUnregisterById0
    • FwpsReleaseClassifyHandle0
    • FwpsCalloutRegister1
    • KeInitializeEvent
    • KeWaitForSingleObject
    • IoAllocateIrp
    • IofCallDriver
    • IoCreateFile
    • IoFreeIrp
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwQueryInformationFile
    • ZwSetInformationFile
    • ZwReadFile
    • ZwWriteFile
    • ZwClose
    • IoFileObjectType
    • strchr
    • strncat
    • strncpy_s
    • strstr
    • KeResetEvent
    • MmProbeAndLockPages
    • MmUnlockPages
    • IoAllocateMdl
    • IoFreeMdl
    • IoReuseIrp
    • __C_specific_handler
    • MmIsAddressValid
    • sprintf
    • KeEnterCriticalRegion
    • KeLeaveCriticalRegion
    • PsTerminateSystemThread
    • KeSetBasePriorityThread
    • CmUnRegisterCallback
    • CmRegisterCallbackEx
    • CmCallbackGetKeyObjectID
    • strncmp
    • strncpy
    • wcsncmp
    • ExAcquireSpinLockExclusive
    • ExReleaseSpinLockExclusive
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeInitializeTimerEx
    • KeSetTimerEx
    • PsCreateSystemThread
    • ZwCreateKey
    • ZwOpenKey
    • ZwFlushKey
    • ZwQueryValueKey
    • ZwSetValueKey
    • NtQueryInformationToken
    • RtlLengthSid
    • RtlConvertSidToUnicodeString
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlSetOwnerSecurityDescriptor
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwOpenProcessTokenEx
    • ZwSetSecurityObject
    • PsGetProcessImageFileName
    • PsProcessType
    • SeExports
    • IoDeleteSymbolicLink
    • ExFreePoolWithTag
    • ExAllocatePoolWithTag
    • KeSetEvent
    • RtlFreeUnicodeString
    • KeBugCheckEx
    • RtlCopyUnicodeString
    • RtlAnsiStringToUnicodeString
    • RtlInitUnicodeString
    • RtlInitAnsiString
    • WskCaptureProviderNPI
    • WskReleaseProviderNPI
    • WskDeregister
    • WskRegister
    • WdfVersionBind
    • WdfVersionBindClass
    • WdfVersionUnbindClass
    • WdfVersionUnbind

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Signature": "0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
          "TBS": {
            "MD5": "a0dd89c33c4973bf6758331e200fb6de",
            "SHA1": "65ff7fa429c0f08f8a8bf30509e8ca2919d9edb5",
            "SHA256": "29a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47",
            "SHA384": "a7ac729302762483ea304ff2660a2ce2f5fa67cbbfc3f6df32a8feafa3852812c9bb8f7050140079aad1dec8119ee88e"
          },
          "ValidFrom": "2020-12-15 22:15:33",
          "ValidTo": "2021-12-02 22:15:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610baac1000000000009",
          "Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "TBS": {
            "MD5": "a569061297e8e824767dbc3184a69bea",
            "SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
            "SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
            "SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
          },
          "ValidFrom": "2012-04-18 23:48:38",
          "ValidTo": "2027-04-18 23:58:38",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2021-04-18 08:09:04
    MD5a57e4e3a3fa46bbdbc9d803283af3479
    SHA14ede7f018c317ddc6a5f8f935f917621668cb1ec
    SHA256f83c357106a7d1d055b5cb75c8414aa3219354deb16ae9ee7efe8ee4c8c670ca
    Authentihash MD51f5f357f730b5852b34876b01fb1d44e
    Authentihash SHA14b8c0445075f09aeef542ab1c86e5de6b06e91a3
    Authentihash SHA2560988d366572a57b3015d875b60704517d05115580678e8f2e126f771eda28f7b
    RichPEHeaderHash MD585bc198af7e82d3ad73505bc7086be84
    RichPEHeaderHash SHA1e652b262f08c568106765e202ea0142129765004
    RichPEHeaderHash SHA2564130707eedc8cb72f6c5703feee7b8bfbdbe7dc34630d6dc33a0f92da20bdb66

    Download

    Certificates

    Expand
    Certificate 33000000b5213fca1e4aa03de40000000000b5
    FieldValue
    ToBeSigned (TBS) MD5a0dd89c33c4973bf6758331e200fb6de
    ToBeSigned (TBS) SHA165ff7fa429c0f08f8a8bf30509e8ca2919d9edb5
    ToBeSigned (TBS) SHA25629a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher
    ValidFrom2020-12-15 22:15:33
    ValidTo2021-12-02 22:15:33
    Signature0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber33000000b5213fca1e4aa03de40000000000b5
    Version3
    Certificate 610baac1000000000009
    FieldValue
    ToBeSigned (TBS) MD5a569061297e8e824767dbc3184a69bea
    ToBeSigned (TBS) SHA1adbb26a587a8f44b4fccaecb306f980d1c55a150
    ToBeSigned (TBS) SHA256cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012
    ValidFrom2012-04-18 23:48:38
    ValidTo2027-04-18 23:58:38
    Signature5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber610baac1000000000009
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • ntoskrnl.exe
    • NETIO.SYS
    • WDFLDR.SYS

    Imported Functions

    Expand
    • FwpmFilterAdd0
    • FwpmFilterDeleteById0
    • FwpsAcquireClassifyHandle0
    • FwpmCalloutAdd0
    • FwpsCompleteClassify0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmTransactionAbort0
    • FwpmTransactionCommit0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpsCalloutUnregisterById0
    • FwpsReleaseClassifyHandle0
    • FwpsCalloutRegister1
    • IoCreateFile
    • IoFreeIrp
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwQueryInformationFile
    • ZwSetInformationFile
    • ZwReadFile
    • ZwWriteFile
    • ZwClose
    • IoFileObjectType
    • KeEnterCriticalRegion
    • KeLeaveCriticalRegion
    • PsTerminateSystemThread
    • KeSetBasePriorityThread
    • sprintf
    • CmUnRegisterCallback
    • CmRegisterCallbackEx
    • CmCallbackGetKeyObjectID
    • MmIsAddressValid
    • strlen
    • strncmp
    • strncpy
    • wcscat
    • wcslen
    • wcsncmp
    • RtlInitAnsiString
    • strcat
    • strcmp
    • strncat
    • IoAllocateIrp
    • ExAcquireSpinLockExclusive
    • ExReleaseSpinLockExclusive
    • wcscpy
    • RtlAnsiStringToUnicodeString
    • RtlFreeUnicodeString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeResetEvent
    • KeInitializeTimerEx
    • KeSetTimerEx
    • PsCreateSystemThread
    • ZwCreateKey
    • ZwOpenKey
    • ZwFlushKey
    • ZwQueryValueKey
    • ZwSetValueKey
    • NtQueryInformationToken
    • RtlLengthSid
    • RtlConvertSidToUnicodeString
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlSetOwnerSecurityDescriptor
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwOpenProcessTokenEx
    • ZwSetSecurityObject
    • PsGetProcessImageFileName
    • PsProcessType
    • SeExports
    • strchr
    • strncpy_s
    • MmProbeAndLockPages
    • MmUnlockPages
    • IoAllocateMdl
    • IoFreeMdl
    • IoReuseIrp
    • __C_specific_handler
    • IofCallDriver
    • ExAllocatePoolWithTag
    • KeWaitForSingleObject
    • KeSetEvent
    • KeInitializeEvent
    • IoDeleteSymbolicLink
    • KeBugCheckEx
    • RtlCopyUnicodeString
    • ExFreePoolWithTag
    • RtlInitUnicodeString
    • strcpy
    • strstr
    • WskCaptureProviderNPI
    • WskReleaseProviderNPI
    • WskDeregister
    • WskRegister
    • WdfVersionBind
    • WdfVersionBindClass
    • WdfVersionUnbindClass
    • WdfVersionUnbind

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Signature": "0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
          "TBS": {
            "MD5": "a0dd89c33c4973bf6758331e200fb6de",
            "SHA1": "65ff7fa429c0f08f8a8bf30509e8ca2919d9edb5",
            "SHA256": "29a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47",
            "SHA384": "a7ac729302762483ea304ff2660a2ce2f5fa67cbbfc3f6df32a8feafa3852812c9bb8f7050140079aad1dec8119ee88e"
          },
          "ValidFrom": "2020-12-15 22:15:33",
          "ValidTo": "2021-12-02 22:15:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610baac1000000000009",
          "Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "TBS": {
            "MD5": "a569061297e8e824767dbc3184a69bea",
            "SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
            "SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
            "SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
          },
          "ValidFrom": "2012-04-18 23:48:38",
          "ValidTo": "2027-04-18 23:58:38",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2021-03-17 07:13:37
    MD59c46269615ae06f912463ddc28319157
    SHA16d6f71e858ce0fad35f4dc6e7ddb72dd0574a497
    SHA25624ea733bae1b8722841fb4c6cead93c4c4f0b1248ca9a21601b1ce6b95b06864
    Authentihash MD5ace17016bb2aba11a9f8f73b2fc98642
    Authentihash SHA1e014c6bebfda944ce3a58ab9fe055d4f9367d49c
    Authentihash SHA256651ffa0c7aff7b4a7695dddd209dc3e7f68156e29a14d3fcc17aef4f2a205dcc
    RichPEHeaderHash MD53b4691d934a09c9e9405216d4916ad8a
    RichPEHeaderHash SHA1beadde6d5d5b7e6a188598980e4ce7540b8e90ca
    RichPEHeaderHash SHA256186f36b59d5535ba21343e53d01b70400138d19e0eebdb55a755ecd612ad08b7

    Download

    Certificates

    Expand
    Certificate 33000000b5213fca1e4aa03de40000000000b5
    FieldValue
    ToBeSigned (TBS) MD5a0dd89c33c4973bf6758331e200fb6de
    ToBeSigned (TBS) SHA165ff7fa429c0f08f8a8bf30509e8ca2919d9edb5
    ToBeSigned (TBS) SHA25629a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher
    ValidFrom2020-12-15 22:15:33
    ValidTo2021-12-02 22:15:33
    Signature0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber33000000b5213fca1e4aa03de40000000000b5
    Version3
    Certificate 610baac1000000000009
    FieldValue
    ToBeSigned (TBS) MD5a569061297e8e824767dbc3184a69bea
    ToBeSigned (TBS) SHA1adbb26a587a8f44b4fccaecb306f980d1c55a150
    ToBeSigned (TBS) SHA256cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012
    ValidFrom2012-04-18 23:48:38
    ValidTo2027-04-18 23:58:38
    Signature5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber610baac1000000000009
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • ntoskrnl.exe
    • NETIO.SYS
    • HAL.dll
    • WDFLDR.SYS

    Imported Functions

    Expand
    • FwpsAcquireClassifyHandle0
    • FwpsReleaseClassifyHandle0
    • FwpmFilterDeleteById0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpmFilterAdd0
    • FwpmCalloutAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmTransactionAbort0
    • FwpmTransactionCommit0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpsCalloutUnregisterById0
    • FwpsCompleteClassify0
    • FwpsCalloutRegister1
    • KeGetCurrentThread
    • KeInitializeEvent
    • KeWaitForSingleObject
    • IoAllocateIrp
    • IofCallDriver
    • IoCreateFile
    • IoFreeIrp
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwQueryInformationFile
    • ZwSetInformationFile
    • ZwReadFile
    • ZwWriteFile
    • ZwClose
    • IoFileObjectType
    • strchr
    • strncat
    • strncpy_s
    • strstr
    • KeResetEvent
    • MmProbeAndLockPages
    • MmUnlockPages
    • IoAllocateMdl
    • IoFreeMdl
    • IoReuseIrp
    • IoDeleteSymbolicLink
    • sprintf
    • KeEnterCriticalRegion
    • KeLeaveCriticalRegion
    • PsTerminateSystemThread
    • KeSetBasePriorityThread
    • CmUnRegisterCallback
    • CmRegisterCallbackEx
    • CmCallbackGetKeyObjectID
    • strncmp
    • strncpy
    • wcsncmp
    • ExAcquireSpinLockExclusive
    • ExReleaseSpinLockExclusive
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeInitializeTimerEx
    • KeSetTimerEx
    • PsCreateSystemThread
    • ZwCreateKey
    • ZwOpenKey
    • ZwFlushKey
    • ZwQueryValueKey
    • ZwSetValueKey
    • NtQueryInformationToken
    • RtlLengthSid
    • RtlConvertSidToUnicodeString
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlSetOwnerSecurityDescriptor
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwOpenProcessTokenEx
    • ZwSetSecurityObject
    • PsGetProcessImageFileName
    • _allmul
    • PsProcessType
    • SeExports
    • memcpy
    • RtlUnwind
    • memset
    • MmIsAddressValid
    • ExFreePoolWithTag
    • ExAllocatePoolWithTag
    • KeSetEvent
    • KeBugCheckEx
    • RtlFreeUnicodeString
    • RtlCopyUnicodeString
    • RtlAnsiStringToUnicodeString
    • RtlInitUnicodeString
    • RtlInitAnsiString
    • WskDeregister
    • WskReleaseProviderNPI
    • WskCaptureProviderNPI
    • WskRegister
    • KeGetCurrentIrql
    • WdfVersionBind
    • WdfVersionBindClass
    • WdfVersionUnbindClass
    • WdfVersionUnbind

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Signature": "0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
          "TBS": {
            "MD5": "a0dd89c33c4973bf6758331e200fb6de",
            "SHA1": "65ff7fa429c0f08f8a8bf30509e8ca2919d9edb5",
            "SHA256": "29a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47",
            "SHA384": "a7ac729302762483ea304ff2660a2ce2f5fa67cbbfc3f6df32a8feafa3852812c9bb8f7050140079aad1dec8119ee88e"
          },
          "ValidFrom": "2020-12-15 22:15:33",
          "ValidTo": "2021-12-02 22:15:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610baac1000000000009",
          "Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "TBS": {
            "MD5": "a569061297e8e824767dbc3184a69bea",
            "SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
            "SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
            "SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
          },
          "ValidFrom": "2012-04-18 23:48:38",
          "ValidTo": "2027-04-18 23:58:38",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2021-05-15 06:46:21
    MD50e2d4679f68796e9dd0d663137cb9e12
    SHA17cb3ea53660dbc1b4fe12e0c03c7bfea0a3c92a2
    SHA2568249e9c0ac0840a36d9a5b9ff3e217198a2f533159acd4bf3d9b0132cc079870
    Authentihash MD58c667904b9db9e69a637c55ae50decbd
    Authentihash SHA1bc2f3850c7b858340d7ed27b90e63b036881fd6c
    Authentihash SHA256f08ebddc11aefcb46082c239f8d97ceea247d846e22c4bcdd72af75c1cbc6b0b
    RichPEHeaderHash MD5f0b684c190bdbac4aa311a7355122963
    RichPEHeaderHash SHA1b7866474ab0a322b84086fccf1948d5a8b7f03a0
    RichPEHeaderHash SHA25633c5dfb8ba99a1d23f6a99cb34c04977b2455fa6c59e79dbad4d910516357bae

    Download

    Certificates

    Expand
    Certificate 33000000b5213fca1e4aa03de40000000000b5
    FieldValue
    ToBeSigned (TBS) MD5a0dd89c33c4973bf6758331e200fb6de
    ToBeSigned (TBS) SHA165ff7fa429c0f08f8a8bf30509e8ca2919d9edb5
    ToBeSigned (TBS) SHA25629a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher
    ValidFrom2020-12-15 22:15:33
    ValidTo2021-12-02 22:15:33
    Signature0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber33000000b5213fca1e4aa03de40000000000b5
    Version3
    Certificate 610baac1000000000009
    FieldValue
    ToBeSigned (TBS) MD5a569061297e8e824767dbc3184a69bea
    ToBeSigned (TBS) SHA1adbb26a587a8f44b4fccaecb306f980d1c55a150
    ToBeSigned (TBS) SHA256cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012
    ValidFrom2012-04-18 23:48:38
    ValidTo2027-04-18 23:58:38
    Signature5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber610baac1000000000009
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • ntoskrnl.exe
    • NETIO.SYS
    • HAL.dll
    • WDFLDR.SYS

    Imported Functions

    Expand
    • FwpsAcquireClassifyHandle0
    • FwpsReleaseClassifyHandle0
    • FwpmFilterDeleteById0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpmFilterAdd0
    • FwpmCalloutAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmTransactionAbort0
    • FwpmTransactionCommit0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpsCalloutUnregisterById0
    • FwpsCompleteClassify0
    • FwpsCalloutRegister1
    • IofCallDriver
    • IoCreateFile
    • IoFreeIrp
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwQueryInformationFile
    • ZwSetInformationFile
    • ZwReadFile
    • ZwWriteFile
    • ZwClose
    • IoFileObjectType
    • KeEnterCriticalRegion
    • KeLeaveCriticalRegion
    • PsTerminateSystemThread
    • KeSetBasePriorityThread
    • sprintf
    • CmUnRegisterCallback
    • CmRegisterCallbackEx
    • CmCallbackGetKeyObjectID
    • MmIsAddressValid
    • strlen
    • strncmp
    • strncpy
    • wcscat
    • wcslen
    • wcsncmp
    • RtlInitAnsiString
    • strcat
    • strcmp
    • strncat
    • ExAllocatePoolWithTag
    • ExAcquireSpinLockExclusive
    • ExReleaseSpinLockExclusive
    • wcscpy
    • RtlAnsiStringToUnicodeString
    • RtlFreeUnicodeString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeResetEvent
    • KeInitializeTimerEx
    • KeSetTimerEx
    • PsCreateSystemThread
    • ZwCreateKey
    • ZwOpenKey
    • ZwFlushKey
    • ZwQueryValueKey
    • ZwSetValueKey
    • NtQueryInformationToken
    • RtlLengthSid
    • RtlConvertSidToUnicodeString
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlSetOwnerSecurityDescriptor
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwOpenProcessTokenEx
    • ZwSetSecurityObject
    • PsGetProcessImageFileName
    • _allmul
    • PsProcessType
    • SeExports
    • strchr
    • strncpy_s
    • MmProbeAndLockPages
    • MmUnlockPages
    • IoAllocateMdl
    • IoFreeMdl
    • IoReuseIrp
    • IoAllocateIrp
    • RtlUnwind
    • KeWaitForSingleObject
    • KeSetEvent
    • KeInitializeEvent
    • KeGetCurrentThread
    • IoDeleteSymbolicLink
    • KeBugCheckEx
    • ExFreePoolWithTag
    • RtlInitUnicodeString
    • RtlCopyUnicodeString
    • strcpy
    • memset
    • memcpy
    • strstr
    • WskDeregister
    • WskReleaseProviderNPI
    • WskCaptureProviderNPI
    • WskRegister
    • KeGetCurrentIrql
    • WdfVersionBind
    • WdfVersionBindClass
    • WdfVersionUnbindClass
    • WdfVersionUnbind

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Signature": "0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
          "TBS": {
            "MD5": "a0dd89c33c4973bf6758331e200fb6de",
            "SHA1": "65ff7fa429c0f08f8a8bf30509e8ca2919d9edb5",
            "SHA256": "29a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47",
            "SHA384": "a7ac729302762483ea304ff2660a2ce2f5fa67cbbfc3f6df32a8feafa3852812c9bb8f7050140079aad1dec8119ee88e"
          },
          "ValidFrom": "2020-12-15 22:15:33",
          "ValidTo": "2021-12-02 22:15:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610baac1000000000009",
          "Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "TBS": {
            "MD5": "a569061297e8e824767dbc3184a69bea",
            "SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
            "SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
            "SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
          },
          "ValidFrom": "2012-04-18 23:48:38",
          "ValidTo": "2027-04-18 23:58:38",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2019-11-03 23:10:09
    MD5f783cf9084f1cefa87e9e5a302d4d18a
    SHA1c1e63efa1447b68a870962334c61cedd04db379b
    SHA25693d99a5fbfc888c0a40a18946933121ae110229dcf206b4d17116a57e7cf4dc9
    Authentihash MD5038cbc948ff5ba06ac0b54ca31401fe4
    Authentihash SHA183660d245fe618ecafe4900ac1e2ad0292c2da2a
    Authentihash SHA25672b99147839bcfb062d29014ec09fe20a8f261748b5925b00171ef3cb849a4c1
    RichPEHeaderHash MD5a53e7b4810b8e8a6646827967165e841
    RichPEHeaderHash SHA16e089a0ffce20d92395e42c69b619bf59c140999
    RichPEHeaderHash SHA2566d1066a1530eeb73686043235fe52052b0934d77e8e9ee471b0c67bfa61172c5

    Download

    Certificates

    Expand
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 09b92d7a420083c94eaf18145cfaedd1
    FieldValue
    ToBeSigned (TBS) MD562acdecc22447b159a7e2efb0350bd63
    ToBeSigned (TBS) SHA1ddd0bd1dded2c9189fc5b8563f8210deb83c590b
    ToBeSigned (TBS) SHA256ae3a19b6b64e739d5d2abb0e1471874b7d8b6b1e3f1e38ed483166a664355a4e
    Subject??=CN, ??=Shanghai, ??=Private Organization, serialNumber=9131010707118381X9, C=CN, ST=Shanghai, L=Shanghai, O=, CN=
    ValidFrom2019-08-27 00:00:00
    ValidTo2022-08-19 12:00:00
    Signature3a72522da9ea787347ffe4ac96c364ffda35372ea83b3427ca0bb30d1478767ed738daaf84648998b3557ff959565e4000ffadb512d64361834b9ad550365a25a69f95ef9e7a4a38294ae14e9edd1724230f84b35deb1cedb5dc3f53d80ddfe9488df913ce93bf1a3989c325424bc35b601a0e85af646c3d764688e1922ba094b4c0e1de92186f4a0d0c1cad81673f9fca92b58e180101d9215fae80d2d42fe02c20fb1602a1cb72ec472d1d4725f1de0f76849cbd02cb7397920c623dbdebe4ea5d94b273ca1180cc5f29b45cc7c064a1bb7fa22f2d8e8e43d85c5e716481cb7beea87bb70eb5672220cec0ba61f08cbffb48114e48c11b1cdc3a13de5d221a
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber09b92d7a420083c94eaf18145cfaedd1
    Version3
    Certificate 0dd0e3374ac95bdbfa6b434b2a48ec06
    FieldValue
    ToBeSigned (TBS) MD5f92649915476229b093c211c2b18e6c4
    ToBeSigned (TBS) SHA12d54c16a8f8b69ccdea48d0603c132f547a5cf75
    ToBeSigned (TBS) SHA2562cd702a7dec30aa441345672e8992ef9770ce4946f276d767b45b0ed627658fb
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert EV Code Signing CA
    ValidFrom2012-04-18 12:00:00
    ValidTo2027-04-18 12:00:00
    Signature9e5b963a2e1288acab016da49f75e40187a3a532d7bcbaa97ea3d61417f7c2136b7c738f2b6ae50f265968b08e259b6ceffa6c939208c14dcf459e9c46d61e74a19b14a3fa012f4ab101e1724048111368b9369d914bd7c2391210c1c4dcbb6214142a615d4f387c661fc61bffadbe4f7f945b7343000f4d73b751cf0ef677c05bcd348cd96313aa0e6111d6f28e27fcb47bb8b91120918678ea0ed428ff2ad52438e837b2ec96bb9fbc4a1650e15ebf517d23a032c7c1949e7ac9c026a2cc2587a0127e749f2d8db1c8e784beb9d1e9debb6a4e887371e12238cb2487e9737e51b2ff98eb4e7e2fe0ca0efab35ed1ba0542a8489f83f63fc4caa8df68a05061
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber0dd0e3374ac95bdbfa6b434b2a48ec06
    Version3

    Imports

    Expand
    • ntoskrnl.exe

    Imported Functions

    Expand
    • MmUnmapLockedPages
    • KeClearEvent
    • IoDeleteSymbolicLink
    • ExFreePoolWithTag
    • IoRegisterPlugPlayNotification
    • KeReadStateEvent
    • MmMapLockedPages
    • RtlInitUnicodeString
    • IoDeleteDevice
    • KeSetEvent
    • KeInitializeEvent
    • KeReleaseSpinLock
    • IoDetachDevice
    • MmBuildMdlForNonPagedPool
    • IoFreeMdl
    • IoCancelIrp
    • KeDelayExecutionThread
    • ObQueryNameString
    • IoDriverObjectType
    • wcsstr
    • MmMapLockedPagesSpecifyCache
    • ExInterlockedInsertHeadList
    • ExAllocatePool
    • ExInterlockedInsertTailList
    • PoStartNextPowerIrp
    • IoUnregisterPlugPlayNotification
    • IofCompleteRequest
    • ObReferenceObjectByHandle
    • IoAttachDeviceToDeviceStack
    • PoCallDriver
    • ExInterlockedRemoveHeadList
    • IoCreateSymbolicLink
    • ObfDereferenceObject
    • ObReferenceObjectByName
    • IoCreateDevice
    • DbgPrint
    • IoAllocateMdl
    • IofCallDriver
    • KeAcquireSpinLockRaiseToDpc
    • KeBugCheckEx
    • __C_specific_handler

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Signature": "0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
          "TBS": {
            "MD5": "a0dd89c33c4973bf6758331e200fb6de",
            "SHA1": "65ff7fa429c0f08f8a8bf30509e8ca2919d9edb5",
            "SHA256": "29a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47",
            "SHA384": "a7ac729302762483ea304ff2660a2ce2f5fa67cbbfc3f6df32a8feafa3852812c9bb8f7050140079aad1dec8119ee88e"
          },
          "ValidFrom": "2020-12-15 22:15:33",
          "ValidTo": "2021-12-02 22:15:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610baac1000000000009",
          "Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "TBS": {
            "MD5": "a569061297e8e824767dbc3184a69bea",
            "SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
            "SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
            "SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
          },
          "ValidFrom": "2012-04-18 23:48:38",
          "ValidTo": "2027-04-18 23:58:38",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2021-05-15 06:17:21
    MD51814c4b16c8c3e746a185daaa5099ebc
    SHA19065b63f7d1b7eac160c10d6f30a097613c29f12
    SHA2560123c7f12dd7530d55aee49949ff1fee911c9689bd04591684aa641882589785
    Authentihash MD59c6ee2cfa1e9a7cf7a847c6d4b20f10e
    Authentihash SHA1faa870b0cb15c9ac2b9bba5d0470bd501ccd4326
    Authentihash SHA2565c206b569b7059b7c32eb5fc36922cb435c2b16c8d96de1038c8bd298ed498fe
    RichPEHeaderHash MD585bc198af7e82d3ad73505bc7086be84
    RichPEHeaderHash SHA1e652b262f08c568106765e202ea0142129765004
    RichPEHeaderHash SHA2564130707eedc8cb72f6c5703feee7b8bfbdbe7dc34630d6dc33a0f92da20bdb66

    Download

    Imports

    Expand
    • fwpkclnt.sys
    • ntoskrnl.exe
    • NETIO.SYS
    • WDFLDR.SYS

    Imported Functions

    Expand
    • FwpmFilterAdd0
    • FwpmFilterDeleteById0
    • FwpsAcquireClassifyHandle0
    • FwpmCalloutAdd0
    • FwpsCompleteClassify0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmTransactionAbort0
    • FwpmTransactionCommit0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpsCalloutUnregisterById0
    • FwpsReleaseClassifyHandle0
    • FwpsCalloutRegister1
    • IoCreateFile
    • IoFreeIrp
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwQueryInformationFile
    • ZwSetInformationFile
    • ZwReadFile
    • ZwWriteFile
    • ZwClose
    • IoFileObjectType
    • KeEnterCriticalRegion
    • KeLeaveCriticalRegion
    • PsTerminateSystemThread
    • KeSetBasePriorityThread
    • sprintf
    • CmUnRegisterCallback
    • CmRegisterCallbackEx
    • CmCallbackGetKeyObjectID
    • MmIsAddressValid
    • strlen
    • strncmp
    • strncpy
    • wcscat
    • wcslen
    • wcsncmp
    • RtlInitAnsiString
    • strcat
    • strcmp
    • strncat
    • IoAllocateIrp
    • ExAcquireSpinLockExclusive
    • ExReleaseSpinLockExclusive
    • wcscpy
    • RtlAnsiStringToUnicodeString
    • RtlFreeUnicodeString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeResetEvent
    • KeInitializeTimerEx
    • KeSetTimerEx
    • PsCreateSystemThread
    • ZwCreateKey
    • ZwOpenKey
    • ZwFlushKey
    • ZwQueryValueKey
    • ZwSetValueKey
    • NtQueryInformationToken
    • RtlLengthSid
    • RtlConvertSidToUnicodeString
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlSetOwnerSecurityDescriptor
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwOpenProcessTokenEx
    • ZwSetSecurityObject
    • PsGetProcessImageFileName
    • PsProcessType
    • SeExports
    • strchr
    • strncpy_s
    • MmProbeAndLockPages
    • MmUnlockPages
    • IoAllocateMdl
    • IoFreeMdl
    • IoReuseIrp
    • __C_specific_handler
    • IofCallDriver
    • ExAllocatePoolWithTag
    • KeWaitForSingleObject
    • KeSetEvent
    • KeInitializeEvent
    • IoDeleteSymbolicLink
    • KeBugCheckEx
    • RtlCopyUnicodeString
    • ExFreePoolWithTag
    • RtlInitUnicodeString
    • strcpy
    • strstr
    • WskCaptureProviderNPI
    • WskReleaseProviderNPI
    • WskDeregister
    • WskRegister
    • WdfVersionBind
    • WdfVersionBindClass
    • WdfVersionUnbindClass
    • WdfVersionUnbind

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Signature": "0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
          "TBS": {
            "MD5": "a0dd89c33c4973bf6758331e200fb6de",
            "SHA1": "65ff7fa429c0f08f8a8bf30509e8ca2919d9edb5",
            "SHA256": "29a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47",
            "SHA384": "a7ac729302762483ea304ff2660a2ce2f5fa67cbbfc3f6df32a8feafa3852812c9bb8f7050140079aad1dec8119ee88e"
          },
          "ValidFrom": "2020-12-15 22:15:33",
          "ValidTo": "2021-12-02 22:15:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610baac1000000000009",
          "Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "TBS": {
            "MD5": "a569061297e8e824767dbc3184a69bea",
            "SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
            "SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
            "SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
          },
          "ValidFrom": "2012-04-18 23:48:38",
          "ValidTo": "2027-04-18 23:58:38",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2021-05-15 06:17:21
    MD50bd3b9f55a2d3a13f506d9d8b970e0de
    SHA1f023177aca17f6dc90fdd9588240cb16c70a9fe2
    SHA25663d61549030fcf46ff1dc138122580b4364f0fe99e6b068bc6a3d6903656aff0
    Authentihash MD59c6ee2cfa1e9a7cf7a847c6d4b20f10e
    Authentihash SHA1faa870b0cb15c9ac2b9bba5d0470bd501ccd4326
    Authentihash SHA2565c206b569b7059b7c32eb5fc36922cb435c2b16c8d96de1038c8bd298ed498fe
    RichPEHeaderHash MD585bc198af7e82d3ad73505bc7086be84
    RichPEHeaderHash SHA1e652b262f08c568106765e202ea0142129765004
    RichPEHeaderHash SHA2564130707eedc8cb72f6c5703feee7b8bfbdbe7dc34630d6dc33a0f92da20bdb66

    Download

    Certificates

    Expand
    Certificate 33000000b5213fca1e4aa03de40000000000b5
    FieldValue
    ToBeSigned (TBS) MD5a0dd89c33c4973bf6758331e200fb6de
    ToBeSigned (TBS) SHA165ff7fa429c0f08f8a8bf30509e8ca2919d9edb5
    ToBeSigned (TBS) SHA25629a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher
    ValidFrom2020-12-15 22:15:33
    ValidTo2021-12-02 22:15:33
    Signature0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber33000000b5213fca1e4aa03de40000000000b5
    Version3
    Certificate 610baac1000000000009
    FieldValue
    ToBeSigned (TBS) MD5a569061297e8e824767dbc3184a69bea
    ToBeSigned (TBS) SHA1adbb26a587a8f44b4fccaecb306f980d1c55a150
    ToBeSigned (TBS) SHA256cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012
    ValidFrom2012-04-18 23:48:38
    ValidTo2027-04-18 23:58:38
    Signature5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber610baac1000000000009
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • ntoskrnl.exe
    • NETIO.SYS
    • WDFLDR.SYS

    Imported Functions

    Expand
    • FwpmFilterAdd0
    • FwpmFilterDeleteById0
    • FwpsAcquireClassifyHandle0
    • FwpmCalloutAdd0
    • FwpsCompleteClassify0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmTransactionAbort0
    • FwpmTransactionCommit0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpsCalloutUnregisterById0
    • FwpsReleaseClassifyHandle0
    • FwpsCalloutRegister1
    • IoCreateFile
    • IoFreeIrp
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwQueryInformationFile
    • ZwSetInformationFile
    • ZwReadFile
    • ZwWriteFile
    • ZwClose
    • IoFileObjectType
    • KeEnterCriticalRegion
    • KeLeaveCriticalRegion
    • PsTerminateSystemThread
    • KeSetBasePriorityThread
    • sprintf
    • CmUnRegisterCallback
    • CmRegisterCallbackEx
    • CmCallbackGetKeyObjectID
    • MmIsAddressValid
    • strlen
    • strncmp
    • strncpy
    • wcscat
    • wcslen
    • wcsncmp
    • RtlInitAnsiString
    • strcat
    • strcmp
    • strncat
    • IoAllocateIrp
    • ExAcquireSpinLockExclusive
    • ExReleaseSpinLockExclusive
    • wcscpy
    • RtlAnsiStringToUnicodeString
    • RtlFreeUnicodeString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeResetEvent
    • KeInitializeTimerEx
    • KeSetTimerEx
    • PsCreateSystemThread
    • ZwCreateKey
    • ZwOpenKey
    • ZwFlushKey
    • ZwQueryValueKey
    • ZwSetValueKey
    • NtQueryInformationToken
    • RtlLengthSid
    • RtlConvertSidToUnicodeString
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlSetOwnerSecurityDescriptor
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwOpenProcessTokenEx
    • ZwSetSecurityObject
    • PsGetProcessImageFileName
    • PsProcessType
    • SeExports
    • strchr
    • strncpy_s
    • MmProbeAndLockPages
    • MmUnlockPages
    • IoAllocateMdl
    • IoFreeMdl
    • IoReuseIrp
    • __C_specific_handler
    • IofCallDriver
    • ExAllocatePoolWithTag
    • KeWaitForSingleObject
    • KeSetEvent
    • KeInitializeEvent
    • IoDeleteSymbolicLink
    • KeBugCheckEx
    • RtlCopyUnicodeString
    • ExFreePoolWithTag
    • RtlInitUnicodeString
    • strcpy
    • strstr
    • WskCaptureProviderNPI
    • WskReleaseProviderNPI
    • WskDeregister
    • WskRegister
    • WdfVersionBind
    • WdfVersionBindClass
    • WdfVersionUnbindClass
    • WdfVersionUnbind

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Signature": "0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
          "TBS": {
            "MD5": "a0dd89c33c4973bf6758331e200fb6de",
            "SHA1": "65ff7fa429c0f08f8a8bf30509e8ca2919d9edb5",
            "SHA256": "29a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47",
            "SHA384": "a7ac729302762483ea304ff2660a2ce2f5fa67cbbfc3f6df32a8feafa3852812c9bb8f7050140079aad1dec8119ee88e"
          },
          "ValidFrom": "2020-12-15 22:15:33",
          "ValidTo": "2021-12-02 22:15:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610baac1000000000009",
          "Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "TBS": {
            "MD5": "a569061297e8e824767dbc3184a69bea",
            "SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
            "SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
            "SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
          },
          "ValidFrom": "2012-04-18 23:48:38",
          "ValidTo": "2027-04-18 23:58:38",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2021-04-09 00:29:46
    MD5a07f5f368deb3569ec3129fa55da4041
    SHA1a10ce0c717bfe0163eda2459964ad637d634de27
    SHA25616b6be03495a4f4cf394194566bb02061fba2256cc04dcbde5aa6a17e41b7650
    Authentihash MD5e03a070a426b0c2de53ea23bfc76086b
    Authentihash SHA1202d5a05e546740037f9a4dc2b21f71680c39d3b
    Authentihash SHA2560391107305d76eb9ddf1a5b3b3c50da361e8ab35b573dbd19bf9383436b9303e
    RichPEHeaderHash MD548c184eea90f0f9d8a01e83867866680
    RichPEHeaderHash SHA1fadd2ab2dd0e54dd2328f37e313b3a7f50f58391
    RichPEHeaderHash SHA256a918abac8859e89b8f2d620f60f54921e2f156a401cfe171a609326331f60635

    Download

    Certificates

    Expand
    Certificate 33000000b5213fca1e4aa03de40000000000b5
    FieldValue
    ToBeSigned (TBS) MD5a0dd89c33c4973bf6758331e200fb6de
    ToBeSigned (TBS) SHA165ff7fa429c0f08f8a8bf30509e8ca2919d9edb5
    ToBeSigned (TBS) SHA25629a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher
    ValidFrom2020-12-15 22:15:33
    ValidTo2021-12-02 22:15:33
    Signature0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber33000000b5213fca1e4aa03de40000000000b5
    Version3
    Certificate 610baac1000000000009
    FieldValue
    ToBeSigned (TBS) MD5a569061297e8e824767dbc3184a69bea
    ToBeSigned (TBS) SHA1adbb26a587a8f44b4fccaecb306f980d1c55a150
    ToBeSigned (TBS) SHA256cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012
    ValidFrom2012-04-18 23:48:38
    ValidTo2027-04-18 23:58:38
    Signature5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber610baac1000000000009
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • ntoskrnl.exe
    • NETIO.SYS
    • HAL.dll
    • WDFLDR.SYS

    Imported Functions

    Expand
    • FwpsAcquireClassifyHandle0
    • FwpsReleaseClassifyHandle0
    • FwpmFilterDeleteById0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpmFilterAdd0
    • FwpmCalloutAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmTransactionAbort0
    • FwpmTransactionCommit0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpsCalloutUnregisterById0
    • FwpsCompleteClassify0
    • FwpsCalloutRegister1
    • memcpy
    • KeGetCurrentThread
    • KeInitializeEvent
    • KeWaitForSingleObject
    • IoAllocateIrp
    • IofCallDriver
    • IoCreateFile
    • IoFreeIrp
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwQueryInformationFile
    • ZwSetInformationFile
    • ZwReadFile
    • ZwWriteFile
    • ZwClose
    • IoFileObjectType
    • strchr
    • strncat
    • strncpy_s
    • KeResetEvent
    • MmProbeAndLockPages
    • MmUnlockPages
    • IoAllocateMdl
    • IoFreeMdl
    • IoReuseIrp
    • memset
    • sprintf
    • KeEnterCriticalRegion
    • KeLeaveCriticalRegion
    • PsTerminateSystemThread
    • KeSetBasePriorityThread
    • CmUnRegisterCallback
    • CmRegisterCallbackEx
    • CmCallbackGetKeyObjectID
    • strncmp
    • strncpy
    • wcsncmp
    • ExAcquireSpinLockExclusive
    • ExReleaseSpinLockExclusive
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeInitializeTimerEx
    • KeSetTimerEx
    • PsCreateSystemThread
    • ZwCreateKey
    • ZwOpenKey
    • ZwFlushKey
    • ZwQueryValueKey
    • ZwSetValueKey
    • NtQueryInformationToken
    • RtlLengthSid
    • RtlConvertSidToUnicodeString
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlSetOwnerSecurityDescriptor
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwOpenProcessTokenEx
    • ZwSetSecurityObject
    • PsGetProcessImageFileName
    • _allmul
    • PsProcessType
    • SeExports
    • IoDeleteSymbolicLink
    • RtlUnwind
    • MmIsAddressValid
    • ExFreePoolWithTag
    • ExAllocatePoolWithTag
    • KeSetEvent
    • RtlFreeUnicodeString
    • KeBugCheckEx
    • RtlAnsiStringToUnicodeString
    • RtlCopyUnicodeString
    • RtlInitUnicodeString
    • RtlInitAnsiString
    • strstr
    • WskDeregister
    • WskReleaseProviderNPI
    • WskCaptureProviderNPI
    • WskRegister
    • KeGetCurrentIrql
    • WdfVersionBind
    • WdfVersionBindClass
    • WdfVersionUnbindClass
    • WdfVersionUnbind

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Signature": "0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
          "TBS": {
            "MD5": "a0dd89c33c4973bf6758331e200fb6de",
            "SHA1": "65ff7fa429c0f08f8a8bf30509e8ca2919d9edb5",
            "SHA256": "29a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47",
            "SHA384": "a7ac729302762483ea304ff2660a2ce2f5fa67cbbfc3f6df32a8feafa3852812c9bb8f7050140079aad1dec8119ee88e"
          },
          "ValidFrom": "2020-12-15 22:15:33",
          "ValidTo": "2021-12-02 22:15:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610baac1000000000009",
          "Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "TBS": {
            "MD5": "a569061297e8e824767dbc3184a69bea",
            "SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
            "SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
            "SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
          },
          "ValidFrom": "2012-04-18 23:48:38",
          "ValidTo": "2027-04-18 23:58:38",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2021-05-15 06:44:55
    MD5cb34374f1b5fb771076872c6b14b7501
    SHA1118f688c30a2f6c2d1feb955f53ce4acf3086b3b
    SHA256e0afb8b937a5907fbe55a1d1cc7574e9304007ef33fa80ff3896e997a1beaf37
    Authentihash MD55064073c3f84f1569377081c4ad33867
    Authentihash SHA1aca8e53483b40a06dfdee81bb364b1622f9156fe
    Authentihash SHA2563d31118a2e92377ecb632bd722132c04af4e65e24ff87743796c75eb07cfcd71
    RichPEHeaderHash MD5f0b684c190bdbac4aa311a7355122963
    RichPEHeaderHash SHA1b7866474ab0a322b84086fccf1948d5a8b7f03a0
    RichPEHeaderHash SHA25633c5dfb8ba99a1d23f6a99cb34c04977b2455fa6c59e79dbad4d910516357bae

    Download

    Certificates

    Expand
    Certificate 33000000b5213fca1e4aa03de40000000000b5
    FieldValue
    ToBeSigned (TBS) MD5a0dd89c33c4973bf6758331e200fb6de
    ToBeSigned (TBS) SHA165ff7fa429c0f08f8a8bf30509e8ca2919d9edb5
    ToBeSigned (TBS) SHA25629a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher
    ValidFrom2020-12-15 22:15:33
    ValidTo2021-12-02 22:15:33
    Signature0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber33000000b5213fca1e4aa03de40000000000b5
    Version3
    Certificate 610baac1000000000009
    FieldValue
    ToBeSigned (TBS) MD5a569061297e8e824767dbc3184a69bea
    ToBeSigned (TBS) SHA1adbb26a587a8f44b4fccaecb306f980d1c55a150
    ToBeSigned (TBS) SHA256cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46
    SubjectC=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012
    ValidFrom2012-04-18 23:48:38
    ValidTo2027-04-18 23:58:38
    Signature5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber610baac1000000000009
    Version3

    Imports

    Expand
    • fwpkclnt.sys
    • ntoskrnl.exe
    • NETIO.SYS
    • HAL.dll
    • WDFLDR.SYS

    Imported Functions

    Expand
    • FwpsAcquireClassifyHandle0
    • FwpsReleaseClassifyHandle0
    • FwpmFilterDeleteById0
    • FwpsAcquireWritableLayerDataPointer0
    • FwpsApplyModifiedLayerData0
    • FwpmFilterAdd0
    • FwpmCalloutAdd0
    • FwpmSubLayerDeleteByKey0
    • FwpmSubLayerAdd0
    • FwpmTransactionAbort0
    • FwpmTransactionCommit0
    • FwpmTransactionBegin0
    • FwpmEngineClose0
    • FwpmEngineOpen0
    • FwpsCalloutUnregisterById0
    • FwpsCompleteClassify0
    • FwpsCalloutRegister1
    • IofCallDriver
    • IoCreateFile
    • IoFreeIrp
    • IoGetRelatedDeviceObject
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwQueryInformationFile
    • ZwSetInformationFile
    • ZwReadFile
    • ZwWriteFile
    • ZwClose
    • IoFileObjectType
    • KeEnterCriticalRegion
    • KeLeaveCriticalRegion
    • PsTerminateSystemThread
    • KeSetBasePriorityThread
    • sprintf
    • CmUnRegisterCallback
    • CmRegisterCallbackEx
    • CmCallbackGetKeyObjectID
    • MmIsAddressValid
    • strlen
    • strncmp
    • strncpy
    • wcscat
    • wcslen
    • wcsncmp
    • RtlInitAnsiString
    • strcat
    • strcmp
    • strncat
    • ExAllocatePoolWithTag
    • ExAcquireSpinLockExclusive
    • ExReleaseSpinLockExclusive
    • wcscpy
    • RtlAnsiStringToUnicodeString
    • RtlFreeUnicodeString
    • RtlCreateSecurityDescriptor
    • RtlSetDaclSecurityDescriptor
    • KeResetEvent
    • KeInitializeTimerEx
    • KeSetTimerEx
    • PsCreateSystemThread
    • ZwCreateKey
    • ZwOpenKey
    • ZwFlushKey
    • ZwQueryValueKey
    • ZwSetValueKey
    • NtQueryInformationToken
    • RtlLengthSid
    • RtlConvertSidToUnicodeString
    • RtlCreateAcl
    • RtlAddAccessAllowedAce
    • RtlSetOwnerSecurityDescriptor
    • PsLookupProcessByProcessId
    • ObOpenObjectByPointer
    • ZwOpenProcessTokenEx
    • ZwSetSecurityObject
    • PsGetProcessImageFileName
    • _allmul
    • PsProcessType
    • SeExports
    • strchr
    • strncpy_s
    • MmProbeAndLockPages
    • MmUnlockPages
    • IoAllocateMdl
    • IoFreeMdl
    • IoReuseIrp
    • IoAllocateIrp
    • RtlUnwind
    • KeWaitForSingleObject
    • KeSetEvent
    • KeInitializeEvent
    • KeGetCurrentThread
    • IoDeleteSymbolicLink
    • KeBugCheckEx
    • ExFreePoolWithTag
    • RtlInitUnicodeString
    • RtlCopyUnicodeString
    • strcpy
    • memset
    • memcpy
    • strstr
    • WskDeregister
    • WskReleaseProviderNPI
    • WskCaptureProviderNPI
    • WskRegister
    • KeGetCurrentIrql
    • WdfVersionBind
    • WdfVersionBindClass
    • WdfVersionUnbindClass
    • WdfVersionUnbind

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Signature": "0d2d53cd15a8feddcb17e2df1bf7dc1aef21e98c6cd220f58b593824849c134a0f1add59ce42ef80ddf47860273013604d9568ec5894a797bd4e571432a9aaf10ab04dd1c038b26ab7c5ca3a9c88d009267fab56254525546a0a055fb37b9cd8029c7d501809fc8b11482c7a4347b3ad29f35427c9570e87117db52cc94864259274b9e2e758f918a3af1fdb9f9d40ffa3ae2e2ae012fb97a436258642a2a4223dc6690db88103a6e5220646bd8afb3d12eb894ac28b527396a1965408487f6ab878b3c474b8c960842861ae8e799a3d2a8d6f918f50f8e26bb1ed6ced47be36e447574e8568582964ff31cd288b9c7f8d7e6a46d6c3d92f5c101fe1522a720c",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
          "TBS": {
            "MD5": "a0dd89c33c4973bf6758331e200fb6de",
            "SHA1": "65ff7fa429c0f08f8a8bf30509e8ca2919d9edb5",
            "SHA256": "29a7b646af062aee3bf37d1ba190211365116db7d7aa4cb87ba268843262ae47",
            "SHA384": "a7ac729302762483ea304ff2660a2ce2f5fa67cbbfc3f6df32a8feafa3852812c9bb8f7050140079aad1dec8119ee88e"
          },
          "ValidFrom": "2020-12-15 22:15:33",
          "ValidTo": "2021-12-02 22:15:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "610baac1000000000009",
          "Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "TBS": {
            "MD5": "a569061297e8e824767dbc3184a69bea",
            "SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
            "SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
            "SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
          },
          "ValidFrom": "2012-04-18 23:48:38",
          "ValidTo": "2027-04-18 23:58:38",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
          "SerialNumber": "33000000b5213fca1e4aa03de40000000000b5",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    source

    last_updated: 2024-09-26