PBProcessMonitor64.sys

PolderbitS Call Recorder

PolderbitS Software

It runs as a Windows 64-bit kernel mode device driver named “PolderbitS Process Monitor Driver”.
Publisher:
PolderbitS Software  (signed and verified)

Product:
PolderbitS Call Recorder

Description:
PolderbitS ProcessMonitor Driver

Version:
1, 0, 0, 16 built by: WinDDK

MD5:
2692fdc27584f2114d35a5864496db74

SHA-1:
225569f8629fe8d5de39ab52dedf60e61a5e3c96

SHA-256:
b266099b720dddbc2fae2663c975332ccdfcb5ffac4f4bab5a6de38a690316ea

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 10:02:16 AM UTC  (today)

File size:
19.7 KB (20,208 bytes)

Product version:
1, 0, 0, 16

Copyright:
Copyright © PolderbitS Software

Original file name:
PBProcessMonitor64.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Program Files\polderbits\call recorder\pbprocessmonitor64.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/11/2010 10:39:17 AM

Valid to:
2/26/2012 9:06:39 AM

Subject:
E=info@polderbits.com, CN=PolderbitS Software, O=PolderbitS Software, S=The Netherlands, C=NL

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012CD4FDD71B

File PE Metadata
Compilation timestamp:
5/13/2011 10:56:23 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
384:OrTow0rlYP405tH6+8tQI0Eod/bAkGzFKYJLdNSbZfdUb+Tis:S8wGl2r5V6Lt8dWVLHius

Entry address:
0x6344

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, A6, FC, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 5C, 00, 44, 00, 65, 00, 76, 00, 69, 00, 63, 00, 65, 00, 5C, 00, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 50, 00, 42, 00, 50, 00, 72, 00, 6F, 00, 63, 00, 65, 00, 73, 00, 73, 00, 4D, 00, 6F, 00, 6E, 00, 69, 00, 74, 00, 6F, 00, 72, 00, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 36, 00, 34, 00...
 
[+]

Entropy:
6.4973

Code size:
8 KB (8,192 bytes)

Driver
Display name:
PolderbitS Process Monitor Driver

Service name:
PBProcessMonitor64

Type:
Kernel device driver (KernelDriver)


Scan PBProcessMonitor64.sys - Powered by Reason Core Security