ndiskhaz.sys

Azzouzi HotSpot

Khalil Azzouzi

It runs as a Windows 64-bit kernel mode device driver named “NDISKHAZ LightWeight Filter”.
Publisher:
Khalil Azzouzi  (signed and verified)

Product:
Azzouzi HotSpot

Description:
NDISKHAZ helper driver

Version:
3.1.2.1

MD5:
e36bff24abdba3db123b3c47dd25fcf7

SHA-1:
8eb84beffb5aaa5cf9f84ec500efb7a6744bb056

SHA-256:
34e7e9d5fa25cca2d4e81843db2aebd49923de740c072e1aea2fef8b0ac63724

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 5:02:46 AM UTC  (today)

File size:
41.4 KB (42,424 bytes)

Product version:
3.1.2.1

Copyright:
Copyright Khalil Azzouzi 2013

Trademarks:
Khalil Azzouzi

Original file name:
ndiskhaz.sys

File type:
Driver (Win64 SYS)

Language:
Language Neutral

Common path:
C:\Windows\System32\drivers\ndiskhaz.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/1/2015 2:25:12 PM

Valid to:
10/20/2018 3:39:17 PM

Subject:
CN=Khalil Azzouzi, O=Khalil Azzouzi, L=Muenster, S=Nordrhein Westfalen, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11210ABE18200573CFF5C267229A1EAC3A63

File PE Metadata
Compilation timestamp:
5/24/2013 3:24:58 PM

OS version:
6.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
11.0

CTPH (ssdeep):
768:hsGV3TwCqPG0icg7ITqNoi4ngNConBpvYZ8AmE3L6BLgT8:hdVjDD7IGKngNpAbz8

Entry address:
0x584C

Entry point:
48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8B, DA, 48, 8B, F9, E8, 17, 4D, 00, 00, 48, 8B, D3, 48, 8B, CF, 48, 8B, 5C, 24, 30, 48, 83, C4, 20, 5F, E9, DE, 48, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 3B, 0D, A9, 28, 00, 00, 75, 12, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 03, C2, 00, 00, 48, C1, C9, 10, E9, 08, 00, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, B9, 02, 00, 00, 00, CD, 29, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00...
 
[+]

Entropy:
6.5088

Code size:
27 KB (27,648 bytes)

Driver
Display name:
NDISKHAZ LightWeight Filter

Service name:
ndiskhaz

Description:
@oem66.inf,%ndiskhaz_Desc%;NDISKHAZ LightWeight Filter

Type:
Kernel device driver (KernelDriver)

Group:
NDIS


Scan ndiskhaz.sys - Powered by Reason Core Security