sysdiag.sys

Huorong Network Security

HuoRongBoRui (Beijing) Technology Co.,Ltd

It runs as a Windows 64-bit kernel mode device driver named “Huorong Network Security Core Kext”.
Publisher:
Huorong Borui (Beijing) Technology Co., Ltd.  (signed by HuoRongBoRui (Beijing) Technology Co.,Ltd)

Product:
Huorong Network Security

Description:
Huorong Network Security Core Kext

Version:
0, 1, 0, 83

MD5:
17d5c2f0a681918cb02c13477e6802dd

SHA-1:
95cf100a8277ceba57e5c450bdca2d1fd719f4d1

SHA-256:
5f673315a6ad013b8fc883a12a0a45241099fa378246c10c04ee42524bc05240

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 7:14:48 PM UTC  (today)

File size:
424.7 KB (434,936 bytes)

Product version:
1, 100, 0, 0

Copyright:
Huorong Security Lab.

Original file name:
sysdiag.sys

File type:
Driver (Win64 SYS)

Language:
English

Common path:
C:\Windows\System32\drivers\sysdiag.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/31/2014 8:00:00 AM

Valid to:
5/31/2015 7:59:59 AM

Subject:
CN="HuoRongBoRui (Beijing) Technology Co.,Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="HuoRongBoRui (Beijing) Technology Co.,Ltd", L=beijing, S=beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3DD7234F019BCA1E4F9BFD1834AD8298

File PE Metadata
Compilation timestamp:
8/29/2014 11:22:29 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

Entry address:
0x5C90

Entry point:
48, 89, 4C, 24, 08, 53, 55, 41, 54, 41, 56, 41, 57, 48, 83, EC, 20, 48, 8B, 05, E8, 34, 03, 00, 33, DB, B9, 28, 0A, 00, 00, 41, BF, 01, 00, 00, 00, 4C, 8B, F2, 44, 8B, E3, 41, 8B, EF, 66, 39, 08, 73, 12, B8, BB, 00, 00, C0, 48, 83, C4, 20, 41, 5F, 41, 5E, 41, 5C, 5D, 5B, C3, 48, 8D, 0D, C4, D9, 05, 00, 33, D2, 41, B8, 88, 04, 00, 00, E8, B7, E2, 02, 00, 48, 8D, 05, 68, DB, 05, 00, 4C, 8D, 1D, 59, DA, 05, 00, 48, 89, 05, 5A, DB, 05, 00, 48, 89, 05, 5B, DB, 05, 00, 48, 8D, 05, D4, DB, 05, 00, 48, 89, 05, CD...
 
[+]

Entropy:
6.7750

Code size:
233.5 KB (239,104 bytes)

Driver
Display name:
Huorong Network Security Core Kext

Service name:
sysdiag

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI

Depends on:
FltMgr


Scan sysdiag.sys - Powered by Reason Core Security