DHProtect.sys

DH Game Protect Engine

HangZhou Electronic Soul Network Technology Co.,Ltd

It runs as a Windows kernel mode device driver named “DHProtect”.
Publisher:
电魂网络科技有限公司  (signed by HangZhou Electronic Soul Network Technology Co.,Ltd)

Product:
DH Game Protect Engine

Version:
1, 3, 2, 1836

MD5:
5bd625f4b95e40626a73e5389ee7af70

SHA-1:
ef22c719b52b268110ed46ab49a754741c27c7ca

SHA-256:
5e0e136c3cf6ed608a5326ac923693f783787b55a3c5bf0e85466639aca3da4c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 5:38:14 PM UTC  (today)

File size:
113.3 KB (116,056 bytes)

Product version:
1, 3, 2, 1836

Copyright:
Copyright (C) 2013

Original file name:
DHProtect.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\dhprotect.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/6/2014 8:00:00 AM

Valid to:
7/5/2017 7:59:59 AM

Subject:
CN="HangZhou Electronic Soul Network Technology Co.,Ltd", OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="HangZhou Electronic Soul Network Technology Co.,Ltd", L=Hangzhou, S=Zhejiang, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
332AC79566FF9A621EE85719B0B4D538

File PE Metadata
Compilation timestamp:
1/12/2017 4:36:46 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

Entry address:
0x2CDD9

Entry point:
E8, D6, E6, FF, FF, 10, D2, FF, 34, 24, 89, 6C, 24, 04, 9C, 9C, FF, 74, 24, 52, C2, 56, 00, 10, D2, 8D, 64, 24, 26, 9C, 60, 66, C7, 44, 24, 04, 48, 5E, FF, 74, 24, 24, C2, 28, 00, 9C, 9C, C6, 44, 24, 04, FA, 8D, 64, 24, 08, 0F, 82, 3B, F0, FE, FF, F8, E8, 4B, 0B, 00, 00, 15, 67, 95, 75, 05, 23, 70, DF, 48, 99, DD, 2E, F3, C3, 82, D8, EF, 43, DC, D1, E5, 75, 23, F4, AA, FF, 8F, 02, 34, 0A, 15, 06, 4F, A4, AF, 93, 45, 19, 35, D8, B5, 2C, 54, 3E, 10, 95, 75, 88, 81, 83, C4, 93, 62, F1, 34, 77, 52, C6, 8C, FA...
 
[+]

Entropy:
7.8450  (probably packed)

Code size:
39.5 KB (40,448 bytes)

Driver
Display name:
DHProtect

Description:
DH Game Protect Engine

Type:
Kernel device driver (KernelDriver)


Scan DHProtect.sys - Powered by Reason Core Security