Information about isafekrnlmon.sys
- File Details
- Overview
- Analysis
isafekrnlmon.sys
File Details
Product Name: |
|
Company Name: |
|
MD5: |
a22e4fc5e5a801daae7978f87059cc9f |
Size: |
51 KB |
First Published: |
2017-05-21 03:01:55 (7 years ago) |
Latest Published: |
2020-11-16 23:11:26 (4 years ago) |
Status: |
Undefined (on last analysis) |
|
Analysis Date: |
2020-11-16 23:11:26 (4 years ago) |
Overview
%programfiles%\elex-tech\yac |
%programfiles%\elex-tech.quarantined\yac |
%temp%\ist5332.tmp\sys\x64 |
%temp%\istcc09.tmp\sys\x64 |
%temp%\istca6f.tmp\sys\x64 |
%temp%\ist4161.tmp\sys\x64 |
%sysdrive%\adwcleaner\quarantine\files\hnejfgjgzqgwsaagtcjzctwkxkwixhhr\yac |
%sysdrive%\adwcleaner\quarantine\files\ttrzbiwbftrphsyswotxgiymvycbwfok\yac |
%temp%\isteda.tmp\sys\x64 |
%temp%\istcdd6.tmp\sys\x64 |
iSafeKrnlMon.sys |
isafekrnlmon.sys |
Taiwan |
20.3% |
|
Vietnam |
16.7% |
|
Hong Kong |
10.7% |
|
South Korea |
5.8% |
|
Thailand |
5.5% |
|
Turkey |
4.8% |
|
India |
4.6% |
|
Indonesia |
4.2% |
|
Poland |
4.0% |
|
France |
2.4% |
|
Brazil |
1.9% |
|
Russia |
1.6% |
|
Romania |
1.2% |
|
Czech Republic |
1.2% |
|
South Africa |
0.9% |
|
Macau |
0.9% |
|
Italy |
0.9% |
|
Spain |
0.9% |
|
Madagascar |
0.9% |
|
Slovakia |
0.7% |
|
Bulgaria |
0.7% |
|
Australia |
0.7% |
|
Ukraine |
0.6% |
|
Hungary |
0.6% |
|
United Arab Emirates |
0.6% |
|
Mexico |
0.6% |
|
Morocco |
0.4% |
|
Myanmar |
0.4% |
|
Argentina |
0.4% |
|
Singapore |
0.4% |
|
Portugal |
0.3% |
|
Luxembourg |
0.3% |
|
Algeria |
0.3% |
|
Germany |
0.3% |
|
China |
0.3% |
|
Azerbaijan |
0.3% |
|
Libya |
0.3% |
|
Malaysia |
0.3% |
|
Chile |
0.1% |
|
Laos |
0.1% |
|
Saint Vincent and the Grenadines |
0.1% |
|
Switzerland |
0.1% |
|
Saudi Arabia |
0.1% |
|
Estonia |
0.1% |
|
Egypt |
0.1% |
|
Israel |
0.1% |
|
Austria |
0.1% |
|
Pakistan |
0.1% |
|
Latvia |
0.1% |
|
United States |
0.1% |
|
Windows 7 |
48.7% |
|
Windows 10 |
39.0% |
|
Windows 8.1 |
8.0% |
|
Windows 8 |
3.4% |
|
Windows XP |
0.7% |
|
Windows Vista |
0.1% |
|
Analysis
Subsystem: |
Native |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000000010000 |
Entry Address: |
0x0000a064 |
Name |
Size of data |
MD5 |
.text |
4096 |
07caea14a98dd3f72c540d8aceee4575 |
.rdata |
4608 |
91575007d757ca9f0cb5fee020bc11e2 |
.data |
7168 |
d5d26f41212c8c7d95d12a21cc7417fc |
.pdata |
1024 |
cbcb49c372264ff7d67ee32c7a093256 |
PAGE |
12288 |
b58f66204e1ea423f79ea64ef9c3d1d0 |
INIT |
3072 |
1e19f548dde392948fedd7d2d764e742 |
.rsrc |
1024 |
b021047ed07db7a09727dca9e5bbeb00 |
.reloc |
512 |
45bfc423a5494a91bd9f63ade6e86345 |