zolsoft.sys

uxthemesrv

博恩斯科技发展有限公司

It runs as a Windows kernel mode device driver named “uxthemesrv”.
Publisher:
OMMOO(Beijing) Corporation  (signed by 博恩斯科技发展有限公司)

Product:
uxthemesrv

Version:
5.00

MD5:
848895d31e5d3b913eb6dfa1b051ba65

SHA-1:
a7d9c5e723a894fcd5f4bb075769505762291786

SHA-256:
c5e52a6b226c09e0fff116f6d922b283b134a50503b4256d7e7487c90463c14c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 10:51:01 PM UTC  (today)

File size:
69.4 KB (71,088 bytes)

Product version:
5.00

Copyright:
Copyright Beijing OMMOO Corporation. All rights reserved.

Original file name:
uxthemesrv.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\zolsoft.sys

Digital Signature
Authority:
WoSign CA Limited

Valid from:
3/10/2014 4:30:01 PM

Valid to:
3/10/2015 4:30:01 PM

Subject:
CN=博恩斯科技发展有限公司, E=contact@ommoo.net, O=博恩斯科技发展有限公司, L=天津市, S=天津市, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
2B164B9960C17A65116C446FB366B019

File PE Metadata
Compilation timestamp:
3/11/2014 5:02:19 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
1536:QhvtRlDPCGuKTE//36Ipdp6pFMJR5jNjPyInhR84SpWBRUMisb+:avQ11fJzjNj6An84hU/

Entry address:
0xDA16

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 1A, FD, FF, FF, 48, 54, 54, 50, 2F, 31, 2E, 31, 20, 33, 30, 32, 20, 46, 6F, 75, 6E, 64, 0D, 0A, 4C, 6F, 63, 61, 74, 69, 6F, 6E, 3A, 20, 68, 74, 74, 70, 3A, 2F, 2F, 24, 31, 46, 39, 36, 37, 33, 43, 32, 46, 2D, 38, 44, 31, 46, 2D, 34, 37, 37, 39, 2D, 42, 32, 33, 39, 2D, 45, 30, 36, 39, 45, 42, 33, 35, 32, 42, 30, 30, 0D, 0A, 43, 6F, 6E, 74, 65, 6E, 74, 2D, 4C, 65, 6E, 67, 74, 68, 3A, 20, 30, 0D, 0A, 0D, 0A, 00, CC, 5C, 28, 2E, 2A, 5C, 29, 5C, 28, 31, 38, 35, 42...
 
[+]

Entropy:
6.7499

Code size:
53.3 KB (54,528 bytes)

Driver
Display name:
uxthemesrv

Type:
Kernel device driver (KernelDriver)


Scan zolsoft.sys - Powered by Reason Core Security