wayprotect64.sys

WayProtect

Btra Away Ltda - ME

It runs as a Windows 64-bit kernel mode device driver named “WayProtect”.
Publisher:
Mist Games EIRELI  (signed by Btra Away Ltda - ME)

Product:
WayProtect

Description:
WayProtect Driver

Version:
3.0.3.0

MD5:
a68c33a1abbbc1a0e6f207451fc581eb

SHA-1:
1f0e40e036b05f9fef4c283d2191c3aa9b53fa05

SHA-256:
14c2631f6cbde831bf32fa4a4d7122cad9a79b9a9ead747e43b41162e6e572f0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 9:34:44 AM UTC  (today)

File size:
1 MB (1,063,128 bytes)

Product version:
3.0.3.0

Copyright:
© Mist Games EIRELI 2017

Original file name:
WayProtect.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Program Files\muaway\wayprotect64.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/3/2016 10:00:00 PM

Valid to:
10/25/2017 9:59:59 PM

Subject:
CN=Btra Away Ltda - ME, O=Btra Away Ltda - ME, L=Maraba, S=Para, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
098AEA8C6EE0141394665E26FEBC8976

File PE Metadata
Compilation timestamp:
2/23/2017 1:42:02 PM

OS version:
6.3

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
12.0

Entry address:
0x15FE74

Entry point:
EB, 08, EF, 54, 0D, 00, 00, 00, 00, 00, E9, 0A, 98, 0C, 00, 48, 0D, 2B, E2, E5, A4, EE, D4, 1D, 2A, 33, D5, D4, 1D, B8, F5, 6B, 2B, E2, 4F, 32, 6B, 2B, E2, 0A, 07, 6B, 2B, E2, D0, 9D, 6B, 2B, E2, 88, 95, 6B, 2B, E2, 3C, 5D, 6B, 2B, E2, AF, E6, 6B, 2B, E2, 09, 4C, 6B, 2B, E2, F3, 96, 6B, 2B, E2, D9, D0, 6B, 2B, E2, 46, 57, 50, 2B, E2, A4, C1, EE, D4, 1D, 63, 16, EE, D4, 1D, D2, 8B, EE, D4, 1D, 18, 69, EE, D4, 1D, C4, B1, EE, D4, 1D, 14, 71, EE, D4, 1D, DF, A2, EE, D4, 1D, 95, D0, 0A, 2B, E2, 43, 3A, 0A, 2B...
 
[+]

Code size:
21.5 KB (22,016 bytes)

Driver
Display name:
WayProtect

Type:
Kernel device driver (KernelDriver)


The file wayprotect64.sys has been discovered within the following program.

MuAwaY  by MuAwaY
www.muaway.net
About 1% of users remove it
 
Powered by Should I Remove It?

Scan wayprotect64.sys - Powered by Reason Core Security