ndiskhaz.sys

Azzouzi HotSpot

Khalil Azzouzi

It runs as a Windows 64-bit kernel mode device driver named “NDISKHAZ LightWeight Filter”.
Publisher:
Khalil Azzouzi  (signed and verified)

Product:
Azzouzi HotSpot

Description:
NDISKHAZ helper driver

Version:
3.1.2.1

MD5:
9d2fa0d2188246ae663ec6caa90aac59

SHA-1:
2555a5d9209c7fe2b6719b7527e7abf59dc47fd1

SHA-256:
035b9729c204e179e0ece221c9a328904decdebacdc696624d4142b4cfc5c746

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 4:36:23 AM UTC  (today)

File size:
41.4 KB (42,424 bytes)

Product version:
3.1.2.1

Copyright:
Copyright Khalil Azzouzi 2013

Trademarks:
Khalil Azzouzi

Original file name:
ndiskhaz.sys

File type:
Driver (Win64 SYS)

Language:
Language Neutral

Common path:
C:\Windows\System32\drivers\ndiskhaz.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/1/2015 3:55:12 PM

Valid to:
10/20/2018 5:09:17 PM

Subject:
CN=Khalil Azzouzi, O=Khalil Azzouzi, L=Muenster, S=Nordrhein Westfalen, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11210ABE18200573CFF5C267229A1EAC3A63

File PE Metadata
Compilation timestamp:
5/24/2013 4:55:14 PM

OS version:
6.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
11.0

CTPH (ssdeep):
768:IzhtGHSf3jrTqMwpjnpTBUABbvBn8Ic0CLYCjqH/E75L6B6gTXp:MhoHyWZpTHZeIc0YGWZwXp

Entry address:
0xA5B8

Entry point:
48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8B, DA, 48, 8B, F9, E8, 83, FF, FF, FF, 48, 8B, D3, 48, 8B, CF, 48, 8B, 5C, 24, 30, 48, 83, C4, 20, 5F, E9, 72, FB, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 4E, 44, 49, 53, 52, 44, 3A, 20, 00, CC, CC, CC, CC, CC, CC, CC, 3D, 3D, 3E, 46, 69, 6C, 74, 65, 72, 52, 65, 67, 69, 73, 74, 65, 72, 44, 65, 76, 69, 63, 65, 0A, 00, CC, CC, CC, CC, CC, CC, CC, 5C, 00, 44, 00, 65, 00, 76, 00, 69, 00, 63, 00, 65, 00, 5C, 00, 4E, 00, 44, 00, 49, 00, 53, 00...
 
[+]

Code size:
27 KB (27,648 bytes)

Driver
Display name:
NDISKHAZ LightWeight Filter

Service name:
ndiskhaz

Type:
Kernel device driver (KernelDriver)

Group:
NDIS


Scan ndiskhaz.sys - Powered by Reason Core Security