Information about ComputerZLock.sys

ComputerZLock.sys

Product Name:

鲁大师

Company Name:

www.ludashi.com

MD5: 6a1de429c1e8e318ef2b56ead5dfc616
Size: 1 MB
First Published: 2018-10-05 15:14:03 (6 years ago)
Latest Published: 2024-09-08 23:01:08 (8 months ago)
Status: Undefined (on last analysis)
Analysis Date: 2024-09-08 23:01:08 (8 months ago)
Signed By: Chengdu Qilu Technology Co. Ltd.
Status: Valid
%appdata%\360bizhi
%programfiles%
%programfiles%\ludashi
%system%\config\systemprofile\appdata\roaming\360bizhi
%temp%
%sysdrive%\00\[新域名ghpym.com]ludashi5.15.18.1125.7z
%system%\config\systemprofile\appdata\roaming\360bizhi
%system%\config\systemprofile\appdata\roaming\360bizhi
%programfiles%\ludashi
%programfiles%\ludashi
Dynwallpaper.sys
ComputerZLock.sys
HardwareProtect.sys
HardwareProtectSlim.sys
HardwareProtectEx.sys
48.6%
35.8%
4.6%
3.7%
2.8%
2.8%
0.9%
0.9%
Windows 10 80.0%
Windows 7 20.0%
Subsystem: Native
PE Type: pe
OS Bitness: 32
Image Base: 0x00010000
Entry Address: 0x006389b5

PE Sections:

Name Size of data MD5
.text 0 00000000000000000000000000000000
.rdata 0 00000000000000000000000000000000
.data 0 00000000000000000000000000000000
INIT 0 00000000000000000000000000000000
.l0 0 00000000000000000000000000000000
.l1 1663488 d42e950d5abb123ce97733cef2f5c67c
.reloc 1536 e88c3007df081a9c6e71ca9c89cb2417
.rsrc 1536 359d2e5622f8dc705f445b341eec31f7

More information: