ring3scan_x64.exe

Ring3 API Hook Scanner

NoVirusThanks Company Srl

Publisher:
NoVirusThanks Company Srl  (signed and verified)

Product:
Ring3 API Hook Scanner

Version:
1.0.0.0

MD5:
123b30f0759ad049937d6ec70f90889f

SHA-1:
5e496aed5c95a449b8081e9daeef12fafd91f256

SHA-256:
72a8d4270c99501e517c35e722820bede42f85980e24de27ece457c4b9b344b9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 9:59:21 AM UTC  (today)

File size:
2.5 MB (2,580,928 bytes)

Product version:
1.0.0.0

Copyright:
NoVirusThanks Company Srl

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\ring3_api_hook_scanner\portable\ring3scan_x64.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
2/21/2012 3:31:16 PM

Valid to:
2/21/2013 3:31:16 PM

Subject:
E=support@novirusthanks.org, CN=NoVirusThanks Company Srl, O=NoVirusThanks Company Srl, L=Castiglione del Lago, S=Perugia, C=IT

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11216CFFA79050D28837AA6F524B364029F6

File PE Metadata
Compilation timestamp:
8/8/2012 1:25:57 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:xX/NRLg3W+xGzaf0dBjSPiZJFVb0eHl/L2Bq4edEaCzdJ3iP:pFRLg3W+xeacdtSZeHlwqFdFCM

Entry address:
0x1DE2E0

Entry point:
55, 48, 83, EC, 20, 48, 8B, EC, 90, 48, 8D, 0D, 98, 49, FF, FF, E8, BB, 2C, E3, FF, 48, 8B, 05, 1C, 96, 02, 00, 48, 8B, 08, E8, CC, 34, FE, FF, 48, 8B, 05, 0D, 96, 02, 00, 48, 8B, 08, B2, 01, E8, 8B, 60, FE, FF, 48, 8B, 05, FC, 95, 02, 00, 48, 8B, 08, 48, 8D, 15, 86, 00, 00, 00, E8, A5, 2C, FE, FF, 48, 8B, 05, E6, 95, 02, 00, 48, 8B, 08, 48, 8B, 15, 44, 25, FF, FF, 4C, 8B, 05, A5, 99, 02, 00, E8, B8, 34, FE, FF, 48, 8B, 05, C9, 95, 02, 00, 48, 8B, 08, 48, 8B, 15, 0F, 1E, FF, FF, 4C, 8B, 05, 48, 8F, 02, 00...
 
[+]

Entropy:
5.8940

Code size:
1.9 MB (1,954,816 bytes)

Scan ring3scan_x64.exe - Powered by Reason Core Security