ssdeep
1536:PhQy2GDoTNx3l7mhrKB3rJ1ucBZsKV5phBuj2pCNsiDjyRHnMcs+Zg5rcS5yZBT:5ABl1usVf6Nui2nMcsYgJcS5yT
TrID
Win32 Executable Generic (58.4%)
Clipper DOS Executable (13.8%)
Generic Win/DOS Executable (13.7%)
DOS Executable Generic (13.7%)
VXD Driver (0.2%)
ExifTool
SubsystemVersion.........: 5.1
LinkerVersion............: 8.0
ImageVersion.............: 6.0
FileSubtype..............: 7
FileVersionNumber........: 1.0.15.4918
UninitializedDataSize....: 0
LanguageCode.............: English (U.S.)
FileFlagsMask............: 0x003f
CharacterSet.............: Unicode
InitializedDataSize......: 36736
FileOS...................: Windows NT 32-bit
MIMEType.................: application/octet-stream
LegalCopyright...........: Copyright (C) GMER 2003-2009
FileVersion..............: 1, 0, 15, 4918 built by: WinDDK
TimeStamp................: 2011:07:16 21:20:40+01:00
FileType.................: Win32 EXE
PEType...................: PE32
InternalName.............: gmer.sys
ProductVersion...........: 1, 0, 15, 4918
FileDescription..........: GMER Driver
http://www.gmer.net
OSVersion................: 6.0
OriginalFilename.........: gmer.sys
Subsystem................: Native
MachineType..............: Intel 386 or later, and compatibles
CompanyName..............: GMER
CodeSize.................: 62976
ProductName..............: GMER
ProductVersionNumber.....: 1.0.15.4918
EntryPoint...............: 0x16005
ObjectFileType...........: Driver
Sigcheck
publisher................: GMER
product..................: GMER
internal name............: gmer.sys
file version.............: 1, 0, 15, 4918 built by: WinDDK
original name............: gmer.sys
copyright................: Copyright (C) GMER 2003-2009
description..............: GMER Driver
http://www.gmer.net
Portable Executable structural information
Compilation timedatestamp.....: 2011-07-16 20:20:40
Target machine................: 332
Entry point address...........: 0x00016005
PE Sections...................:
Name Virtual Address Virtual Size Raw Size Entropy MD5
.text 1152 59948 60032 6.45 a0ffd8d7e67fda16d045b3b9c0142509
.rwtext 61184 81 128 1.71 c00d6d7ba9be2d7a526fdd7311b1247f
.rdata 61312 12220 12288 5.14 d5bbf44c1f811f2d9f8454ba69b8c008
.data 73600 16452 16512 0.34 74ff1bbfb8e0ed1825669d220a13bc03
INIT 90112 2728 2816 5.43 619c6618a9e220cb810a7c9a63a55a26
.rsrc 92928 880 896 3.35 c0c6d76b43cfd61d2ad6fb7fc4b40a16
.reloc 93824 6938 7040 6.44 278d1556f5baf102668f4df3707ad15b
PE Imports....................:
HAL.dll
KfLowerIrql, KeGetCurrentIrql, KfRaiseIrql
ntoskrnl.exe
ExFreePoolWithTag, ExAllocatePool, ZwReadFile, ZwQueryInformationFile, ZwOpenFile, memcpy, KeQuerySystemTime, PsLookupProcessByProcessId, ObfDereferenceObject, ObReferenceObjectByHandle, KeDetachProcess, KeAttachProcess, MmIsAddressValid, memset, ZwSetInformationFile, RtlInitUnicodeString, ObOpenObjectByPointer, IofCompleteRequest, IoDeleteDevice, IoDeleteSymbolicLink, RtlUnicodeStringToAnsiString, PsTerminateSystemThread, PsCreateSystemThread, KeInitializeEvent, wcsstr, IoCreateSymbolicLink, IoCreateDevice, PsGetVersion, strrchr, KeGetCurrentThread, KeBugCheckEx, IoFreeIrp, _wcsnicmp, IoAllocateIrp, IoGetBaseFileSystemDeviceObject, ZwWriteFile, ZwCreateFile, strncmp, IoGetCurrentProcess, strncpy, _vsnprintf, PsGetCurrentProcessId, _snprintf, RtlTimeToTimeFields, ExSystemTimeToLocalTime, _stricmp, ZwQuerySystemInformation, _strnicmp, RtlCopyUnicodeString, ZwQueryValueKey, ZwOpenKey, ZwSetValueKey, _snwprintf, ZwClose, MmUnlockPages, MmProbeAndLockPages, IoAllocateMdl, ZwEnumerateKey, PsLookupThreadByThreadId, RtlAnsiStringToUnicodeString, RtlInitAnsiString, _strupr, _strlwr, KeDelayExecutionThread, RtlVolumeDeviceToDosName, ObfReferenceObject, IoGetDeviceObjectPointer, wcschr, wcsncmp, KeInsertQueueDpc, KeSetTargetProcessorDpc, KeInitializeDpc, KeNumberProcessors, MmMapLockedPagesSpecifyCache, KeServiceDescriptorTable, _wcsicmp, wcsrchr, strchr, strstr, wcsncpy, IoCreateNotificationEvent, ZwQuerySection, RtlInitString, ZwRequestWaitReplyPort, ZwConnectPort, MmMapLockedPages, MmGetSystemRoutineAddress, ObReferenceObjectByName, IoDriverObjectType, ZwDeleteFile, KeTickCount, NtClose, IofCallDriver, RtlCompareUnicodeString, IoBuildSynchronousFsdRequest, _alldiv, RtlEqualUnicodeString, ZwQueryDirectoryObject, ZwOpenDirectoryObject, ZwQuerySymbolicLinkObject, ZwOpenSymbolicLinkObject, IoGetDeviceInterfaces, KeBugCheck, KeSetEvent, KeWaitForSingleObject, IoFreeMdl, KeClearEvent, RtlUnwind
First seen by VirusTotal
2011-07-17 05:09:05 UTC ( 6 mois, 4 semaines ago )
Last seen by VirusTotal
2012-02-10 22:31:38 UTC ( 3 minutes ago )
File names (max. 25)
ugliyaoc.sys
kwtiyfow.sys
smona_49c9df7fb2200e3e20aedb8f8a69aa28bf858adfbc3ae286957d2479832abb8b.bin
pxtdypow.vys
577c37fbeb973390e61b654d0ac1bebd
ugldipow.sys
afgiakog.sys
577c37fbeb973390e61b654d0ac1bebd
smona132751277393395068577
pxtdypod.sys1
kwdyypow.sys
577c37fbeb973390e61b654d0ac1bebd
577c37fbeb973390e61b654d0ac1bebd
zaccess.sys
1.sys
577c37fbeb973390e61b654d0ac1bebd
577c37fbeb973390e61b654d0ac1bebd.uxldqpoc.sys.bad
9ACCD0DD0067FF858A190133D8846F00D61A8267.sys
C:\kfddapow.sys
Suspect_kwdirpod.sys.vir
afgiipoc.-ys
aflirpow.sys
aglcyuoc.sys
awaiikob.sys
awddyfow.sys