Hooksys.sys

Rising security Software 2010

Beijing Rising Information Technology Corporation Limited

It runs as a Windows 64-bit kernel mode device driver named “hooksys”.
Publisher:
Beijing Rising Information Technology Co., Ltd.  (signed by Beijing Rising Information Technology Corporation Limited)

Product:
Rising security Software 2010

Description:
Hooksys for AMD64

Version:
24, 0, 0, 3

MD5:
fb38a8ee34da11e88545d07c7bed72e0

SHA-1:
7a7ce871326c27bd0e07c1cc52237a0af39d022c

SHA-256:
0a6a89b20338565afab1c0f9c1c9fc5bf6038cf149036124746b39a1c18052b3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 2:31:42 AM UTC  (today)

File size:
35.6 KB (36,504 bytes)

Product version:
24.00

Copyright:
Copyright(C) 2009-2010 Beijing Rising Information Technology Co., Ltd. All Rights Reserved.

Original file name:
Hooksys.sys

File type:
Driver (Win64 SYS)

Common path:
C:\Windows\System32\drivers\hooksys.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/23/2009 9:00:00 AM

Valid to:
7/23/2012 8:59:59 AM

Subject:
CN=Beijing Rising Information Technology Corporation Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Beijing Rising Information Technology Corporation Limited, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
484D09D50F2997425272B797AA28A557

File PE Metadata
Compilation timestamp:
2/1/2010 4:06:57 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
8.0

Entry address:
0x3B10

Entry point:
53, 56, 57, 48, 83, EC, 70, 48, 8B, F1, E8, 25, 1C, 00, 00, B9, 78, 00, 00, 00, E8, 87, F9, FF, FF, 48, 85, C0, 74, 68, 48, 8B, C8, E8, DA, 12, 00, 00, 48, 89, 05, BB, 3D, 00, 00, 48, 85, C0, 0F, 84, D0, 00, 00, 00, B9, 90, 00, 00, 00, E8, 60, F9, FF, FF, 48, 85, C0, 74, 59, 48, 8B, C8, E8, F3, 0E, 00, 00, 48, 89, 05, 8C, 3D, 00, 00, 48, 85, C0, 75, 52, 48, 8B, 1D, 88, 3D, 00, 00, 48, 85, DB, 0F, 84, 9D, 00, 00, 00, 48, 8B, CB, E8, BF, 15, 00, 00, 48, 8B, CB, E8, 47, F9, FF, FF, B8, 01, 00, 00, C0, 48, 83...
 
[+]

Entropy:
6.2667

Code size:
20 KB (20,480 bytes)

Driver
Display name:
hooksys

Type:
Kernel device driver (KernelDriver)


Scan Hooksys.sys - Powered by Reason Core Security