Information about isafekrnlboot.sys
- File Details
- Overview
- Analysis
isafekrnlboot.sys
File Details
Product Name: |
|
Company Name: |
|
MD5: |
fab2eba07369bf3c6db33469b5b36fcb |
Size: |
53 KB |
First Published: |
2017-05-21 03:01:55 (7 years ago) |
Latest Published: |
2020-11-16 22:43:44 (4 years ago) |
Status: |
Undefined (on last analysis) |
|
Analysis Date: |
2020-11-16 22:43:44 (4 years ago) |
Overview
%system%\drivers |
%programfiles%\elex-tech\yac |
%temp%\ist5332.tmp\sys\x64 |
%temp%\istcc09.tmp\sys\x64 |
%temp%\istca6f.tmp\sys\x64 |
%temp%\ist4161.tmp\sys\x64 |
%sysdrive%\adwcleaner\quarantine\files\hnejfgjgzqgwsaagtcjzctwkxkwixhhr\yac |
%sysdrive%\adwcleaner\quarantine\files\ttrzbiwbftrphsyswotxgiymvycbwfok\yac |
%temp%\isteda.tmp\sys\x64 |
%temp%\istd3bf.tmp\sys\x64 |
iSafeKrnlBoot.sys |
isafekrnlboot.sys |
0A031C952FEEDD56C28A70F95D9A623595933E3F.sys |
iSafeKrnlBoot.sys.18.53.09.66.vz |
$REQ3CHM.sys |
iSafeKrnlBoot.sys.quarantined |
dshbkowdcomwqjrcymbokkvlhqturehw.back |
akpyvzxujcyeplcqffvjijrbpjiapzhi.back |
xbhljkbliielsixzcrdvpnisnolwcpjp.back |
|
26.7% |
|
|
15.9% |
|
|
13.3% |
|
|
5.7% |
|
|
5.6% |
|
|
4.8% |
|
|
4.1% |
|
|
3.7% |
|
|
2.4% |
|
|
2.2% |
|
|
1.3% |
|
|
1.2% |
|
|
0.9% |
|
|
0.8% |
|
|
0.8% |
|
|
0.7% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.5% |
|
|
0.4% |
|
|
0.4% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
Windows 7 |
49.6% |
|
Windows 10 |
40.0% |
|
Windows 8.1 |
7.3% |
|
Windows 8 |
2.7% |
|
Windows XP |
0.3% |
|
Windows Vista |
0.1% |
|
Windows Server 2012 R2 |
0.1% |
|
Analysis
Subsystem: |
Native |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000000010000 |
Entry Address: |
0x0000c090 |
Name |
Size of data |
MD5 |
.text |
2560 |
8a086d15d0fad0cb6705397842f27204 |
.rdata |
3584 |
8c501600da646681c55fe03f13a6c0a7 |
.data |
6656 |
877d6b58b0c31bbf96da4a0b191676f0 |
.pdata |
1024 |
3e985861d0089e92514ce09565a78a9b |
PAGE |
19456 |
9d6d81b99be5e7000ab8cccade9902cb |
INIT |
1536 |
a416d0671b58f440f7e2e3ddacd38bd2 |
.rsrc |
1024 |
b3fa9fd8d5517a2c96a549333d82ea9f |
.reloc |
512 |
57152ccf8f98cceb7e6afaf773deac1f |