MEmuDrv.sys

MEmu

上海迈微软件科技有限公司

It runs as a Windows 64-bit kernel mode device driver named “memudrv”.
Publisher:
Microvirt Corporation  (signed by 上海迈微软件科技有限公司)

Product:
MEmu

Description:
MemuHyperv Support Driver

Version:
4.3.20.96996

MD5:
671b4318dc927a121a2c4f9a0e7ff771

SHA-1:
41b72efba7f6d7b278147c85c03dd9159e9c0357

SHA-256:
2981bf3713ee25e8634eabc84e3fece545c0d2e572cb3e2bffe55e61afa3c7f3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 11:12:54 AM UTC  (today)

File size:
254.3 KB (260,368 bytes)

Product version:
4.3.20.r96996

Copyright:
Copyright (C) 2009-2015 Microvirt Corporation

Original file name:
MEmuDrv.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Program Files\microvirt\memuhyperv\memudrv.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/12/2015 10:00:00 AM

Valid to:
1/19/2016 9:59:59 AM

Subject:
CN=上海迈微软件科技有限公司, O=上海迈微软件科技有限公司, L=Shanghai, S=Shanghai, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
077A1C45282C3EB635E9914E64ABE9C3

File PE Metadata
Compilation timestamp:
11/2/2015 11:11:35 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
10.0

Entry address:
0xE270

Entry point:
40, 57, 48, 83, EC, 60, 48, 8B, 15, 63, DA, 01, 00, 4C, 8D, 05, 7C, F2, FF, FF, 48, 8B, F9, 49, 3B, D0, 74, 17, 48, 8D, 0D, CD, DC, 01, 00, E8, D8, 6A, 01, 00, B8, E5, 00, 00, C0, 48, 83, C4, 60, 5F, C3, 33, C9, 48, 89, 5C, 24, 70, E8, 01, DE, 00, 00, 85, C0, 0F, 88, 5F, 01, 00, 00, 48, 8B, CF, E8, B1, EE, FF, FF, 8B, D8, 85, C0, 0F, 88, 3C, 01, 00, 00, 48, 8B, 05, 98, 84, 02, 00, 33, D2, 41, B8, 28, 09, 01, 00, 48, 8B, 58, 40, 48, 8B, CB, E8, 4C, DC, 00, 00, BA, C0, 07, 00, 00, 48, 8B, CB, E8, 5F, A4, FF...
 
[+]

Code size:
146.5 KB (150,016 bytes)

Driver
Display name:
memudrv

Type:
Kernel device driver (KernelDriver)


Scan MEmuDrv.sys - Powered by Reason Core Security