WiseRegNotify.sys

WiseRegNotify

Lespeed Technology Ltd.

It runs as a Windows 64-bit kernel mode device driver named “WiseRegNotify”.
Publisher:
WiseCleaner.com  (signed by Lespeed Technology Ltd.)

Product:
WiseRegNotify

Description:
WiseCleaner.com

Version:
1.1.1.15

MD5:
2df09b4bdaf29e155e84f94180e6d9b0

SHA-1:
31b08958ae9bdb959ba08619186efe35fe97e5ee

SHA-256:
ce0c829148fff04b1a6a203313b025590358962407f0df2e86437deaed924066

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 1:43:46 AM UTC  (today)

File size:
27.4 KB (28,080 bytes)

Product version:
1.1.1.15

Copyright:
Copyright (C) 2016

Original file name:
WiseRegNotify.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\windows\wiseregnotify.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/6/2015 9:00:00 PM

Valid to:
5/14/2017 8:59:59 PM

Subject:
CN=Lespeed Technology Ltd., O=Lespeed Technology Ltd., L=BeiJing, S=BeiJing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
57C76F616CBD9AEB18B22862A09D94DC

File PE Metadata
Compilation timestamp:
2/28/2017 6:43:08 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
10.0

Entry address:
0x1850

Entry point:
48, 89, 5C, 24, 10, 56, 48, 83, EC, 60, 48, 8B, D9, 48, 8D, 15, 24, 39, 00, 00, 48, 8D, 0D, 3D, 39, 00, 00, FF, 15, 37, 38, 00, 00, 48, 8D, 15, 50, 39, 00, 00, 48, 8D, 4C, 24, 40, FF, 15, 95, 37, 00, 00, 33, F6, 4C, 8D, 1D, 7C, 47, 00, 00, 4C, 89, 5C, 24, 30, 4C, 8D, 44, 24, 40, 44, 8D, 4E, 22, 33, D2, 48, 8B, CB, C6, 44, 24, 28, 00, 89, 74, 24, 20, FF, 15, F2, 37, 00, 00, 85, C0, 0F, 88, BF, 00, 00, 00, 48, 8D, 05, C3, 00, 00, 00, 48, 8D, 15, 34, 39, 00, 00, 48, 8D, 4C, 24, 50, 48, 89, 43, 70, 48, 8D, 05...
 
[+]

Code size:
15 KB (15,360 bytes)

Driver
Display name:
WiseRegNotify

Type:
Kernel device driver (KernelDriver)


Scan WiseRegNotify.sys - Powered by Reason Core Security