ardrv.sys

AppRemover

OPSWAT, Inc.

Publisher:
OPSWAT, Inc.  (signed and verified)

Product:
AppRemover

Version:
4.2.6.1

MD5:
c566b60a3a4f36d4b3b3ec2562556860

SHA-1:
025e12d4c8c516a562a84da062846e87416fffc0

SHA-256:
2d67f8c5cbe631695d294a4ddf9a844f29d43db0ea89d21703e1a94abb98639d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 12:54:41 PM UTC  (today)

File size:
227.3 KB (232,784 bytes)

Product version:
4.2.6.1

Copyright:
© OPSWAT, Inc. All rights reserved.

Original file name:
AppRemover.exe

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\00000001\sidegrade\ardrv.sys

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
6/2/2015 5:30:00 AM

Valid to:
9/1/2018 5:29:59 AM

Subject:
CN="OPSWAT, Inc.", O="OPSWAT, Inc.", L=San Francisco, S=California, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
1CA9CC01747A11B1EAAF103C8D9A9E6C

File PE Metadata
Compilation timestamp:
2/5/2017 4:02:03 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

Entry address:
0x403E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, E0, D1, FF, FF, CC, CC, AC, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 2C, 43, 00, 00, 20, 20, 00, 00, 8C, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, C2, 43, 00, 00, 00, 20, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 9C, 43, 00, 00, 88, 43, 00, 00, 76, 43, 00, 00, 62, 43, 00, 00, 4E, 43, 00, 00, 3A, 43, 00, 00, AE, 43, 00, 00, 00, 00, 00, 00, B0, 41, 00, 00, BA, 41, 00, 00, C8, 41, 00, 00, D8, 41, 00, 00, E4, 41...
 
[+]

Entropy:
3.2249

Code size:
3 KB (3,072 bytes)

Scan ardrv.sys - Powered by Reason Core Security