dhprotectx64.sys

DH Game Protect Engine

HangZhou Electronic Soul Network Technology Co.,Ltd

It runs as a Windows 64-bit kernel mode device driver named “DHProtect”.
Publisher:
电魂网络科技有限公司  (signed by HangZhou Electronic Soul Network Technology Co.,Ltd)

Product:
DH Game Protect Engine

Version:
1, 3, 2, 1836

MD5:
544f355815227c15fecc59990a46ff12

SHA-1:
cede343d582f9fa9005c8f48b9369d4137f3df1b

SHA-256:
b53bdff924edca0587c0d6a2921acf3cbb7ac0e638ad465a12e7a87280acb24a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 5:49:42 PM UTC  (today)

File size:
115.3 KB (118,104 bytes)

Product version:
1, 3, 2, 1836

Copyright:
Copyright (C) 2013

Original file name:
DHProtect.sys

File type:
Driver (Win64 SYS)

Common path:
C:\Windows\System32\drivers\dhprotectx64.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/6/2014 8:00:00 AM

Valid to:
7/5/2017 7:59:59 AM

Subject:
CN="HangZhou Electronic Soul Network Technology Co.,Ltd", OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="HangZhou Electronic Soul Network Technology Co.,Ltd", L=Hangzhou, S=Zhejiang, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
332AC79566FF9A621EE85719B0B4D538

File PE Metadata
Compilation timestamp:
1/12/2017 4:36:38 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

Entry address:
0x27E5C

Entry point:
E9, CB, 93, 00, 00, 0F, 84, 6B, 3E, FF, FF, F8, F8, 2C, 30, F5, E9, E0, F1, FF, FF, E9, 0F, 6E, FF, FF, F5, F8, F8, 3D, 7F, 00, 00, 00, E9, 01, 90, 00, 00, E9, 51, 45, 00, 00, E9, E3, 36, 00, 00, 0F, 84, F8, 6B, FF, FF, 10, F9, 48, 01, C2, 66, D3, D9, F6, D9, D0, F9, 8B, 8E, 8C, 00, 00, 00, F9, 66, 0F, A3, D7, F5, E9, 8D, 34, FF, FF, FE, C8, E9, 67, 61, FF, FF, E9, 67, 28, 00, 00, 84, EC, 38, C6, 39, F1, 48, 01, C7, F8, E9, 67, 3B, FF, FF, 0F, 82, B3, 95, 00, 00, E9, BF, 40, 00, 00, E9, 6C, 27, FF, FF, E9...
 
[+]

Entropy:
7.6711

Packer / compiler:
Xtreme-Protector v1.05

Code size:
38.5 KB (39,424 bytes)

Driver
Display name:
DHProtect

Description:
DH Game Protect Engine

Type:
Kernel device driver (KernelDriver)


Scan dhprotectx64.sys - Powered by Reason Core Security