5943b267-64f3-40d4-8669-354f23dec122

Agent64.sys :inline

Description

Agent64.sys is a vulnerable driver and more information will be added as found.

  • UUID: 5943b267-64f3-40d4-8669-354f23dec122
  • Created: 2023-01-09
  • Author: Michael Haag
  • Acknowledgement: |

Download

This download link contains the vulnerable driver!

Commands

sc.exe create Agent64.sys binPath=C:\windows\temp\Agent64.sys type=kernel && sc.exe start Agent64.sys
Use CasePrivilegesOperating System
Elevate privilegeskernelWindows 10

Detections

YARA 🏹

Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed driver files

Sigma 🛡️

Expand

Names

detects loading using name only

Hashes

detects loading using hashes only

Sysmon 🔎

Expand

Block

on hashes

Alert

on hashes

Resources


  • https://github.com/namazso/physmem_drivers
  • https://github.com/namazso/physmem_drivers

  • Known Vulnerable Samples

    PropertyValue
    FilenameAgent64.sys
    Creation Timestamp2009-12-14 03:23:26
    MD58407ddfab85ae664e507c30314090385
    SHA18db869c0674221a2d3280143cbb0807fac08e0cc
    SHA25605f052c64d192cf69a462a5ec16dda0d43ca5d0245900c9fcb9201685a2e7748
    Authentihash MD5d86884546c97e614b73d16c600cfb2df
    Authentihash SHA194f7575a6bb378d0cf85b3dc65941c95415e7a80
    Authentihash SHA2563bc0cec99dce687304dad8f7a6daf772e695cbd0169d346d03ae12500361a1e8
    RichPEHeaderHash MD5dd9ea0c6c3773a8caf1a86726551af41
    RichPEHeaderHash SHA145509ef0d417fb2a30496adc9511d048e4730f98
    RichPEHeaderHash SHA2565b467c45ee29fdaba31eff00eacc8db61940f94a9bf6a357c0663c58b2cd752b
    Publisher"eSupport.com, Inc.", Phoenix Technologies Ltd, "eSupport.com, Inc"
    CompanyPhoenix Technologies
    DescriptionDriverAgent Direct I/O for 64-bit Windows
    ProductDriverAgent
    OriginalFilenameAgent64.sys

    Download

    Certificates

    Expand
    Certificate 0400000000012f4ee152d7
    FieldValue
    ToBeSigned (TBS) MD5e140543fe3256027cfa79fc3c19c1776
    ToBeSigned (TBS) SHA1c655f94eb1ecc93de319fc0c9a2dc6c5ec063728
    ToBeSigned (TBS) SHA2563ca71e85908ff67368e4dc00253f5691b9e6d50c966e7784143d75fb92aa3448
    SubjectC=BE, O=GlobalSign nv,sa, CN=GlobalSign Timestamping CA , G2
    ValidFrom2011-04-13 10:00:00
    ValidTo2028-01-28 12:00:00
    Signature4e5e56901e46b4d94931f3bb1739281bc216ddfd41dc0905049b6fb2a29ad6992e40990055b5ea3fa52076d38634d417cc553ac782eeefa8babcd8069f1550dfcd167b523a02d7191afdaff0785ce04bc518df3a241edaacb8a95804020730dbb0125efe31bef00448f4f070f83a5e5683cf3dfb0dbcf4c5ed979db9d4dba52784e3389b8ba735864420a43b6da46a0ba183fd28ebdaef28f6cc885dfb0a3b00abe021ebe22f356c0f8e344597eba2f79933357ecb9a8abb454de73f9fc2d98afa65b26ec77e65ffe892e12c31a2f7b02736488f266f3bee4d761f79c3e57f9635bc2d0ecc01b08e7fff518080a792d4b34446648c874f166307314b63b0dff3
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber0400000000012f4ee152d7
    Version3
    Certificate 0400000000013189c637e8
    FieldValue
    ToBeSigned (TBS) MD50140a61a07f5dfb1d7d3c66ec7d6a916
    ToBeSigned (TBS) SHA138cf80255975d689f1ab266a85bc72335a82e41f
    ToBeSigned (TBS) SHA25679a79284a0ef2db92bc02b235895de02ee6a15bb7ee233185d4567f9fc3d1d1a
    SubjectC=BE, O=GlobalSign nv,sa, CN=GlobalSign CodeSigning CA , SHA256 , G2
    ValidFrom2011-08-02 10:00:00
    ValidTo2019-08-02 10:00:00
    Signature79b06934e20587f6fed4602c2f86793403e0b107930c845cf9e4dc6ccf6eb5ec0a5cba0bd068312e3f64bd0f826b6677817fc629a517d8f0894d832411f66efe9de1480a28a0e27b2480a4ecc29a00d7b06d6ccd88d51578cf13f988a5734dc1362bdccbcedb7e7cd28bef2fbdb34f4d3aadbb626e2893c40ccbd9e6cae011029403b0bd3f942856901e53c227d5c93ccd1a631e825915b640caa781aac355af33d1b575e809ea47084822fb5d1bf32c7a697ec5d75a5e56333cad57e8932542c3d25e713b4a1c54eda955ac2805c7c46c5ddc3c93f6693c8251ce1a153d5e0173ff40a2eab4aed38efaee5d6c47c741f5d45657f2183732d6d4cc4bf671e076
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber0400000000013189c637e8
    Version3
    Certificate 04000000000125071df9af
    FieldValue
    ToBeSigned (TBS) MD5f47739306d14722e670d9436eadb8e4f
    ToBeSigned (TBS) SHA1457d9df00a652cb4c3356d00145d9528fc309172
    ToBeSigned (TBS) SHA256bd1765c56594221373893ef26d97f88c144fb0e5a0111215b45d7239c3444df7
    SubjectOU=GlobalSign Root CA , R3, O=GlobalSign, CN=GlobalSign
    ValidFrom2009-11-18 10:00:00
    ValidTo2019-03-18 10:00:00
    Signature4252a97ea2cf5b3bcb4bddbaf85759d324a47772ef62443782ed06ee04d5165f24a314dc6c54056ab09b3dda8139daad28db956f8183f5cd62b14524b1dd29e5085495958cf01d065f1ad6463f1340174811169b474dd13ab50f571c9230d0f8b2253b0acdf687f9c7b257d33f7da58c14ce9ca8c79f4693da59fa795d652035445a4fc1909dc1549256dc34c8f5c103d05dc059489c00fc95a0f1d176f71636c813927f2d2bc0b880f126261f414d52bf1e97bb018208e715f6c1d5342accf5e4c3877a5781e1d6d74286620177e2a9c47a86f404387a076a7d00ec73f7a80b3478c59eb3efb838400e8c3353c875ec5f3eea755eff820e7415dc1905f3ba31
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber04000000000125071df9af
    Version3
    Certificate 112106a081d33fd87ae5824cc16b52094e03
    FieldValue
    ToBeSigned (TBS) MD5a0ac4d48fe852f7b3ed4e623d59a825f
    ToBeSigned (TBS) SHA1d4db9846bc4d7db142eeb364286f6de7c102420c
    ToBeSigned (TBS) SHA25678d2e41a13eb4e9171bae2d2adb192cf39210b5231f77cda936bcfbe8c003bdf
    SubjectC=SG, O=GMO GlobalSign Pte Ltd, CN=GlobalSign TSA for MS Authenticode , G2
    ValidFrom2015-02-03 00:00:00
    ValidTo2026-03-03 00:00:00
    Signature8032dc078d1ca09c9d3c2ae83d218b59a14d7ecc44ce03be7eaabcc4e67b73bb4bf188da904e7537283863b9d72b0f54a956ce7739973073cd9bd9d905451c8da4b8035d4fd91c2e98e0e988e6ecd7057e562a7bf7165ba3ad8f972512841bb25c634a0ad2ef10544782843569289c0ce41f141624fa75dc74726e4ecae36a43afcf7d3648d1bde906912c2fa6c871fdcfbdd89d2198fcafdbde228cafa7f377ef9ddca3704b441af078851ef2a58c39b5dc881c37edad14f5070b26bdbe6d025eb1b8b0586c853a0df6ff5a270cc5de53e7543c564cc94e4c30f6f25cfb1a8cc282bead5991f61b4d557bcf5b01dcfd7ad36f235c32479b01f3c15114468a9b
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber112106a081d33fd87ae5824cc16b52094e03
    Version3
    Certificate 11216e054fad930d88cabc078eb0d3bcc8ac
    FieldValue
    ToBeSigned (TBS) MD507ff655cdba156b39f88d802c992ebf3
    ToBeSigned (TBS) SHA13c8d5517e4d30167f270e3543d5e2ce2bf467070
    ToBeSigned (TBS) SHA256a065dcc26ff157388fbb81ef23454b8eaf2deaa4794040f4bf1afb6a6d79d0a7
    SubjectC=US, ST=MA, L=North Andover, O=eSupport.com, Inc., CN=eSupport.com, Inc.
    ValidFrom2014-09-24 20:36:26
    ValidTo2015-09-25 20:36:26
    Signature386e2be7e95562b52e95ae0e00ab2181b2d671a2d324c96e5512d8af948dd9e15d42aafe5431ae079857b9c35ccd663ba7c0fef04974f27d8bf8a384fd5489393bdacf6dee7067f5ea9f11311e4a1b3b917c866eaee253c8edd08fc79e25bca7e0c0e892d4f0d65cce1aea7e4813c53d8baa708ad6ee167c4b6ba2cf88a6f29661aab4cd73062532812338ca25950c06dc45becdf28ee42048c9cbaa8ec58c8f2afb18b82e0b7ef389417c48900b41e4093c664ab69bbf35fb7af80baefd1781999e6b119ff8bf21245611aa6c2cd356631c67e1dd9c69da25746b7f543014be046ef19b1cf9a5bfd0594d8816f83aa590588e9501166b85ed40961885fb54f7
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber11216e054fad930d88cabc078eb0d3bcc8ac
    Version3
    Certificate 6129152700000000002a
    FieldValue
    ToBeSigned (TBS) MD50bb058d116f02817737920f112d9fd3b
    ToBeSigned (TBS) SHA1fd116235171a4feafedee586b7a59185fb5fd7e6
    ToBeSigned (TBS) SHA256f970426cc46d2ae0fc5f899fa19dbe76e05f07e525654c60c3c9399492c291f4
    SubjectC=BE, O=GlobalSign nv,sa, OU=Root CA, CN=GlobalSign Root CA
    ValidFrom2011-04-15 19:55:08
    ValidTo2021-04-15 20:05:08
    Signature5ff8d065746a81c6a6ca5b03b6914ae84bbdef2ba142f0efb4a5adcd3389ec0b9585ac62501108aa58d25aa08310e5a6337af25af2c5fe787cf09c83df190ad97396002dd62ccde914d41d9de83f3c1a76f7904efb01350a6c9313a0c356eb67a0e4d17a96dec267f190f80a7bf5321b94ec5f751f8d1b34da6c58a7cb2d279e2226b7c9aa30cc0777b836e38201b5393ccc8dd9a75f7f23b3877fdb5798918bd7ce2520e39d644fdd87f72b68490318e0a5df7c5f68644d36838d4781f2e9e0a869abfa7b163c05a449ea8830190a6c73055178dfd41ddd3ad47f2de44e54be83431e7a7433b4a4ebd77073bc2a02988966eef6bc8f749378e329025a5a43e258ce7ccf9acad236893be25fda26054ec8d4e72c910e1797c5beee8b13112323294ffa83d050f6bafad53db3173df4ff034aa325dce67561d1fa35086bd62744d068b78d45e0eb852cc8a15d614474160e5958aed2b5eea5bcd6d7076ab62978fd976767dd8d4f17944fd2ed0caf972437c3a29c81da6be143b6577b4cecbf791319e79fe844e94781b75e701e91f83dd17b27f50b7056434805dda92fab86101d0b12e31ad04c6e75ded645b30b748887935c564a41029af7aeb799d8b67f88fa11f2457cf4d71b91c01cf1a0fbd4080a411a142acef4eb34486e66879ed54b7a397fbb0e3d3861cf735706e412066bd96b5308cd7018c22d4f974691bca9f0
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber6129152700000000002a
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • KeInitializeDpc
    • IofCompleteRequest
    • IoCreateSymbolicLink
    • IoCreateDevice
    • IofCallDriver
    • ExFreePoolWithTag
    • ExAllocatePool
    • ZwClose
    • MmUnmapLockedPages
    • IoDeleteDevice
    • KeSetEvent
    • MmFreeContiguousMemory
    • MmUnmapIoSpace
    • IoFreeMdl
    • ZwUnmapViewOfSection
    • IoConnectInterrupt
    • IoDisconnectInterrupt
    • IoStartNextPacket
    • KeInsertQueueDpc
    • MmMapLockedPages
    • ZwMapViewOfSection
    • MmBuildMdlForNonPagedPool
    • MmGetPhysicalAddress
    • MmMapLockedPagesSpecifyCache
    • ObReferenceObjectByHandle
    • ZwOpenSection
    • IoAllocateMdl
    • MmAllocateContiguousMemory
    • KeBugCheckEx
    • RtlInitUnicodeString
    • _snwprintf
    • IoCreateNotificationEvent
    • IoDeleteSymbolicLink
    • HalTranslateBusAddress
    • HalGetInterruptVector
    • KeStallExecutionProcessor

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "0400000000012f4ee152d7",
          "Signature": "4e5e56901e46b4d94931f3bb1739281bc216ddfd41dc0905049b6fb2a29ad6992e40990055b5ea3fa52076d38634d417cc553ac782eeefa8babcd8069f1550dfcd167b523a02d7191afdaff0785ce04bc518df3a241edaacb8a95804020730dbb0125efe31bef00448f4f070f83a5e5683cf3dfb0dbcf4c5ed979db9d4dba52784e3389b8ba735864420a43b6da46a0ba183fd28ebdaef28f6cc885dfb0a3b00abe021ebe22f356c0f8e344597eba2f79933357ecb9a8abb454de73f9fc2d98afa65b26ec77e65ffe892e12c31a2f7b02736488f266f3bee4d761f79c3e57f9635bc2d0ecc01b08e7fff518080a792d4b34446648c874f166307314b63b0dff3",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign Timestamping CA , G2",
          "TBS": {
            "MD5": "e140543fe3256027cfa79fc3c19c1776",
            "SHA1": "c655f94eb1ecc93de319fc0c9a2dc6c5ec063728",
            "SHA256": "3ca71e85908ff67368e4dc00253f5691b9e6d50c966e7784143d75fb92aa3448",
            "SHA384": "d9d366f9328f2b55ee19a32cc5fd5148b81d764282fe5dc196c872ae249caa51d2c212ef39f33945dfe0cda81925e326"
          },
          "ValidFrom": "2011-04-13 10:00:00",
          "ValidTo": "2028-01-28 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "0400000000013189c637e8",
          "Signature": "79b06934e20587f6fed4602c2f86793403e0b107930c845cf9e4dc6ccf6eb5ec0a5cba0bd068312e3f64bd0f826b6677817fc629a517d8f0894d832411f66efe9de1480a28a0e27b2480a4ecc29a00d7b06d6ccd88d51578cf13f988a5734dc1362bdccbcedb7e7cd28bef2fbdb34f4d3aadbb626e2893c40ccbd9e6cae011029403b0bd3f942856901e53c227d5c93ccd1a631e825915b640caa781aac355af33d1b575e809ea47084822fb5d1bf32c7a697ec5d75a5e56333cad57e8932542c3d25e713b4a1c54eda955ac2805c7c46c5ddc3c93f6693c8251ce1a153d5e0173ff40a2eab4aed38efaee5d6c47c741f5d45657f2183732d6d4cc4bf671e076",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign CodeSigning CA , SHA256 , G2",
          "TBS": {
            "MD5": "0140a61a07f5dfb1d7d3c66ec7d6a916",
            "SHA1": "38cf80255975d689f1ab266a85bc72335a82e41f",
            "SHA256": "79a79284a0ef2db92bc02b235895de02ee6a15bb7ee233185d4567f9fc3d1d1a",
            "SHA384": "5fcadd07057f8358148fca22ad424498f8e1a97bb55317e4426f809000542988867e0c44d0175950450653e0d20dd83a"
          },
          "ValidFrom": "2011-08-02 10:00:00",
          "ValidTo": "2019-08-02 10:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "04000000000125071df9af",
          "Signature": "4252a97ea2cf5b3bcb4bddbaf85759d324a47772ef62443782ed06ee04d5165f24a314dc6c54056ab09b3dda8139daad28db956f8183f5cd62b14524b1dd29e5085495958cf01d065f1ad6463f1340174811169b474dd13ab50f571c9230d0f8b2253b0acdf687f9c7b257d33f7da58c14ce9ca8c79f4693da59fa795d652035445a4fc1909dc1549256dc34c8f5c103d05dc059489c00fc95a0f1d176f71636c813927f2d2bc0b880f126261f414d52bf1e97bb018208e715f6c1d5342accf5e4c3877a5781e1d6d74286620177e2a9c47a86f404387a076a7d00ec73f7a80b3478c59eb3efb838400e8c3353c875ec5f3eea755eff820e7415dc1905f3ba31",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "OU=GlobalSign Root CA , R3, O=GlobalSign, CN=GlobalSign",
          "TBS": {
            "MD5": "f47739306d14722e670d9436eadb8e4f",
            "SHA1": "457d9df00a652cb4c3356d00145d9528fc309172",
            "SHA256": "bd1765c56594221373893ef26d97f88c144fb0e5a0111215b45d7239c3444df7",
            "SHA384": "b8b268a1bdf388be66a1c969b7b353cb2bbc9fad446049b7efa05a9ab3b714494e97f4d1ee1c0bae35bfd9bf6ef275b3"
          },
          "ValidFrom": "2009-11-18 10:00:00",
          "ValidTo": "2019-03-18 10:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "112106a081d33fd87ae5824cc16b52094e03",
          "Signature": "8032dc078d1ca09c9d3c2ae83d218b59a14d7ecc44ce03be7eaabcc4e67b73bb4bf188da904e7537283863b9d72b0f54a956ce7739973073cd9bd9d905451c8da4b8035d4fd91c2e98e0e988e6ecd7057e562a7bf7165ba3ad8f972512841bb25c634a0ad2ef10544782843569289c0ce41f141624fa75dc74726e4ecae36a43afcf7d3648d1bde906912c2fa6c871fdcfbdd89d2198fcafdbde228cafa7f377ef9ddca3704b441af078851ef2a58c39b5dc881c37edad14f5070b26bdbe6d025eb1b8b0586c853a0df6ff5a270cc5de53e7543c564cc94e4c30f6f25cfb1a8cc282bead5991f61b4d557bcf5b01dcfd7ad36f235c32479b01f3c15114468a9b",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=SG, O=GMO GlobalSign Pte Ltd, CN=GlobalSign TSA for MS Authenticode , G2",
          "TBS": {
            "MD5": "a0ac4d48fe852f7b3ed4e623d59a825f",
            "SHA1": "d4db9846bc4d7db142eeb364286f6de7c102420c",
            "SHA256": "78d2e41a13eb4e9171bae2d2adb192cf39210b5231f77cda936bcfbe8c003bdf",
            "SHA384": "990ed96dca5979deeedc98a012279f04efb5559d7e7f5084a12f3802ee9439326557aecefd081cff739b78515b5d7f50"
          },
          "ValidFrom": "2015-02-03 00:00:00",
          "ValidTo": "2026-03-03 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "11216e054fad930d88cabc078eb0d3bcc8ac",
          "Signature": "386e2be7e95562b52e95ae0e00ab2181b2d671a2d324c96e5512d8af948dd9e15d42aafe5431ae079857b9c35ccd663ba7c0fef04974f27d8bf8a384fd5489393bdacf6dee7067f5ea9f11311e4a1b3b917c866eaee253c8edd08fc79e25bca7e0c0e892d4f0d65cce1aea7e4813c53d8baa708ad6ee167c4b6ba2cf88a6f29661aab4cd73062532812338ca25950c06dc45becdf28ee42048c9cbaa8ec58c8f2afb18b82e0b7ef389417c48900b41e4093c664ab69bbf35fb7af80baefd1781999e6b119ff8bf21245611aa6c2cd356631c67e1dd9c69da25746b7f543014be046ef19b1cf9a5bfd0594d8816f83aa590588e9501166b85ed40961885fb54f7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=MA, L=North Andover, O=eSupport.com, Inc., CN=eSupport.com, Inc.",
          "TBS": {
            "MD5": "07ff655cdba156b39f88d802c992ebf3",
            "SHA1": "3c8d5517e4d30167f270e3543d5e2ce2bf467070",
            "SHA256": "a065dcc26ff157388fbb81ef23454b8eaf2deaa4794040f4bf1afb6a6d79d0a7",
            "SHA384": "e9c4de5f60539f7237e8d371e15b74bcc18d5b329fa6545c422b0c400f98d6c1e482c5a9b98e61c5ab8958c76e226976"
          },
          "ValidFrom": "2014-09-24 20:36:26",
          "ValidTo": "2015-09-25 20:36:26",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "6129152700000000002a",
          "Signature": "5ff8d065746a81c6a6ca5b03b6914ae84bbdef2ba142f0efb4a5adcd3389ec0b9585ac62501108aa58d25aa08310e5a6337af25af2c5fe787cf09c83df190ad97396002dd62ccde914d41d9de83f3c1a76f7904efb01350a6c9313a0c356eb67a0e4d17a96dec267f190f80a7bf5321b94ec5f751f8d1b34da6c58a7cb2d279e2226b7c9aa30cc0777b836e38201b5393ccc8dd9a75f7f23b3877fdb5798918bd7ce2520e39d644fdd87f72b68490318e0a5df7c5f68644d36838d4781f2e9e0a869abfa7b163c05a449ea8830190a6c73055178dfd41ddd3ad47f2de44e54be83431e7a7433b4a4ebd77073bc2a02988966eef6bc8f749378e329025a5a43e258ce7ccf9acad236893be25fda26054ec8d4e72c910e1797c5beee8b13112323294ffa83d050f6bafad53db3173df4ff034aa325dce67561d1fa35086bd62744d068b78d45e0eb852cc8a15d614474160e5958aed2b5eea5bcd6d7076ab62978fd976767dd8d4f17944fd2ed0caf972437c3a29c81da6be143b6577b4cecbf791319e79fe844e94781b75e701e91f83dd17b27f50b7056434805dda92fab86101d0b12e31ad04c6e75ded645b30b748887935c564a41029af7aeb799d8b67f88fa11f2457cf4d71b91c01cf1a0fbd4080a411a142acef4eb34486e66879ed54b7a397fbb0e3d3861cf735706e412066bd96b5308cd7018c22d4f974691bca9f0",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=BE, O=GlobalSign nv,sa, OU=Root CA, CN=GlobalSign Root CA",
          "TBS": {
            "MD5": "0bb058d116f02817737920f112d9fd3b",
            "SHA1": "fd116235171a4feafedee586b7a59185fb5fd7e6",
            "SHA256": "f970426cc46d2ae0fc5f899fa19dbe76e05f07e525654c60c3c9399492c291f4",
            "SHA384": "c0df876be008c26ca407fe904e6f5e7ccded17f9c16830ce9f8022309c9e64c97f494810f152811ae43e223b82ad7cc6"
          },
          "ValidFrom": "2011-04-15 19:55:08",
          "ValidTo": "2021-04-15 20:05:08",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign CodeSigning CA , SHA256 , G2",
          "SerialNumber": "11216e054fad930d88cabc078eb0d3bcc8ac",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    FilenameAgent64.sys
    Creation Timestamp2009-12-14 03:23:26
    MD51ed08a6264c5c92099d6d1dae5e8f530
    SHA127d3ebea7655a72e6e8b95053753a25db944ec0f
    SHA2564045ae77859b1dbf13972451972eaaf6f3c97bea423e9e78f1c2f14330cd47ca
    Authentihash MD5d86884546c97e614b73d16c600cfb2df
    Authentihash SHA194f7575a6bb378d0cf85b3dc65941c95415e7a80
    Authentihash SHA2563bc0cec99dce687304dad8f7a6daf772e695cbd0169d346d03ae12500361a1e8
    RichPEHeaderHash MD5dd9ea0c6c3773a8caf1a86726551af41
    RichPEHeaderHash SHA145509ef0d417fb2a30496adc9511d048e4730f98
    RichPEHeaderHash SHA2565b467c45ee29fdaba31eff00eacc8db61940f94a9bf6a357c0663c58b2cd752b
    Publisher"eSupport.com, Inc.", Phoenix Technologies Ltd, "eSupport.com, Inc"
    CompanyPhoenix Technologies
    DescriptionDriverAgent Direct I/O for 64-bit Windows
    ProductDriverAgent
    OriginalFilenameAgent64.sys

    Download

    Certificates

    Expand
    Certificate 3825d7faf861af9ef490e726b5d65ad5
    FieldValue
    ToBeSigned (TBS) MD5d6c7684e9aaa508cf268335f83afe040
    ToBeSigned (TBS) SHA118066d20ad92409c567cdfde745279ff71c75226
    ToBeSigned (TBS) SHA256a612fb22ce8be6dab75e47c98508f98496583e79c9c97b936a8caee9ea9f3fff
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services Signer , G2
    ValidFrom2007-06-15 00:00:00
    ValidTo2012-06-14 23:59:59
    Signature50c54bc82480dfe40d24c2de1ab1a102a1a6822d0c831581370a820e2cb05a1761b5d805fe88dbf19191b3561a40a6eb92be3839b07536743a984fe437ba9989ca95421db0b9c7a08d57e0fad5640442354e01d133a217c84daa27c7f2e1864c02384d8378c6fc53e0ebe00687dda4969e5e0c98e2a5bebf8285c360e1dfad28d8c7a54b64dac71b5bbdac3908d53822a1338b2f8a9aebbc07213f44410907b5651c24bc48d34480eba1cfc902b414cf54c716a3805cf9793e5d727d88179e2c43a2ca53ce7d3df62a3ab84f9400a56d0a835df95e53f418b3570f70c3fbf5ad95a00e17dec4168060c90f2b6e8604f1ebf47827d105c5ee345b5eb94932f233
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber3825d7faf861af9ef490e726b5d65ad5
    Version3
    Certificate 47bf1995df8d524643f7db6d480d31a4
    FieldValue
    ToBeSigned (TBS) MD5518d2ea8a21e879c942d504824ac211c
    ToBeSigned (TBS) SHA121ce87d827077e61abddf2beba69fde5432ea031
    ToBeSigned (TBS) SHA2561ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA
    ValidFrom2003-12-04 00:00:00
    ValidTo2013-12-03 23:59:59
    Signature4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber47bf1995df8d524643f7db6d480d31a4
    Version3
    Certificate 040000000001239e0facb3
    FieldValue
    ToBeSigned (TBS) MD55ccf05e4dec10d9d6fe15d8778325272
    ToBeSigned (TBS) SHA179f0a648bd7f1184f86bff43ae47c9ecc3ed3cec
    ToBeSigned (TBS) SHA25633ea31b892ba274a4aefe545de45c42c218b6dff78146655cdea892545c2cccc
    SubjectC=BE, O=GlobalSign nv,sa, OU=Primary Object Publishing CA, CN=GlobalSign Primary Object Publishing CA
    ValidFrom1999-01-28 13:00:00
    ValidTo2017-01-27 12:00:00
    Signatureb578a6a27c04b77fc97f7d6abc71fa293060c2f4621efe7f431e9b6ee2b21f730b85765b7df54e49062fd4fab79140efed6f8d8e138354c52a023d0aa4dc990b7abd772fcc40c18ff3c48c4e72ba107ce6ff642bc7ce6ca7fcd79a7c8e468d01834d423bdb9c3f9f326157d717b0b33666f0b3fd446f8137b1944ea7562589f58ad66d116262795c42900218d39c23fc08e86445b92d7e805b4eafc38a299283781f914134af85c5fd07994e2c5cfec7fd17bb2525314d72b5b5294b489a376f13c7114e4a451e7e2f319cabe852afd6679734885f0e276a6652d15ac7ac302c2038dd2bff3aebce104582a27b1ba12073569b2a93e60451066c1bdc2f899493
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber040000000001239e0facb3
    Version3
    Certificate 010000000001257ee1f400
    FieldValue
    ToBeSigned (TBS) MD5ed0acf60cdd337b9e0a2ab818d7733c6
    ToBeSigned (TBS) SHA1e5a9eb7de851eb17fed066190a6c4e8b13cc908b
    ToBeSigned (TBS) SHA256ddb82ae2aaed1a98b7c6c84378f622064b4e0e3f9b2abb57819eeba31eabee40
    SubjectC=US, ST=MA, L=North Andover, O=Phoenix Technologies Ltd, OU=eSupport, CN=Phoenix Technologies Ltd
    ValidFrom2009-12-11 17:20:45
    ValidTo2010-12-12 17:20:42
    Signaturea7d9a2c70e374ebde881422b81fab976d3182885474a1379d078c736dc5e32157c8b5c667ec3e4bfb078a7f1e90e27be2bad1a41c54e9b53fcdf4f53c55a4a6e1328c147ca683314ae76a64e00d0487ae707f63c1c8524b5245329d368f7cbe263c7982dc73fe20c76921d51ad2a4333baba7443b5f493d42e8a2abcc510371a0a8a6b549cc41484d1da2442ce77e29284e7a6c1c64f2597e2cef45d2e97e1bb74826cab053233cfffed1d55c0c65b6bdefe00c5817dcbe798aa13bb7fb5c909348d5968c7f049f99943fbe0cf8be7e68fee1c6b45b911ecb1e11683a719be94109894e0c39d50530bbb9d0d2db812b78893f9ed0a870f9f6196268ed35ef119
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber010000000001257ee1f400
    Version3
    Certificate 040000000001239e0faf24
    FieldValue
    ToBeSigned (TBS) MD57dd2351a85d3665eeb6720a21f4f7dee
    ToBeSigned (TBS) SHA177838c4d7f36958a581841d28f481d61ce0696ed
    ToBeSigned (TBS) SHA256846725f4b0193468c1079d6127e9e6e420fc6ed66019ed02d732ba644decad57
    SubjectC=BE, O=GlobalSign nv,sa, OU=ObjectSign CA, CN=GlobalSign ObjectSign CA
    ValidFrom2004-01-22 10:00:00
    ValidTo2017-01-27 10:00:00
    Signature1e6af36df48ea922fe7008652ea15dab3330dd6c78fa4beaadc58dec107a6ac55897396b92f391e20ca7281cd15d768e8b077c136fadc43643b3c1bc3159cf1838d8a33bceffca6758bfe0f1ac613ea23b1ebc025b41ac446bf526f3ed5ea865f6ca65a63fcaf577eba5862a582956f8be161040e9d2fc572c636137662539202e0703a036032594bd7ceb7ed3a3c2c57616753092b9ff7641352168d10e5e5c8ec30360e68040fcc05da2546e6e9267a7811287a2a32bdbb74dffe4d5c7e505e6d5f1aefccd661821f33e47c9e59542612c9d2680b20fa83d0ec9a778df6e748c2c46f672e93c646b2855c44b6433cb78541338f0d57106d43e0d0a350ee0b3
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber040000000001239e0faf24
    Version3
    Certificate 610b7f6b000000000019
    FieldValue
    ToBeSigned (TBS) MD54798d55be7663a75649cda4dedc686ef
    ToBeSigned (TBS) SHA10f1ab2937b245d9466ea6f9bf056a5942e3989cf
    ToBeSigned (TBS) SHA256ef14ea05bb066ee9f4188196dd69cd769b283ac4d7555db52f5e76922d3456e1
    SubjectC=BE, O=GlobalSign nv,sa, OU=Root CA, CN=GlobalSign Root CA
    ValidFrom2006-05-23 17:00:51
    ValidTo2016-05-23 17:10:51
    Signature13c56c5e077f3c57ff9b315f3fbd955425c679f92c31034d64694b56d95b976f7cf3f0d024657538639813701613f7a701f1c623e085866c0bf080945a75e87ce41e92b473bfc1b3a7b00bd31884cbcc09a35c9c4f3eb03a9c2d1bc404ef9737966fe5ecbaac6ab3d4e23cdf8b25e7acbc624531dda40a72e41bf8784301ccba3914de5d90aed85acf5eca46815133d5a60e5867d3d8665888169beeb11acaad91138421da9a6e20efda007428bac95ff34d5dc3da25692554ea44bcc39b29331cd63c961f8781c553d72a2733d42e197c08586ddb4e1999a9ea5ff39a9d8c513a5a5cbd2fa908359b54a7db351a521633343aa380046afdb4838cad90cf0c3a6596ec334e1826b849bbeb8192ff134d324b23c733e7b6716b15f69c80e6bcb76cbe41d5033a7133150050743b0e5df996aaed903eab134c809926bc38a5eb0236891db620be83ab10f8199ed76379d4aeb12f6136f94a4ba833c70e7241f9f1b1907eae46efde397b75a0411459041d42bc4788b8130e05fa1df0808dff70c677d84bdc460e231a72d5bfdefeaaae69583cfc5c46e4d5819a8b6e6559771a32a590a6b6649364fd0753c9a0de28ad2a6cc638d181ce98f54019e92c1743a4265fd3443053e41d02baa40a2f16dd7a60275242bbad98372897e4b8d27911e3108c48d5305d0a0c52def588ea8d1a2d67c9f4801484b7850cd16628a5c66f2461
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber610b7f6b000000000019
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • KeInitializeDpc
    • IofCompleteRequest
    • IoCreateSymbolicLink
    • IoCreateDevice
    • IofCallDriver
    • ExFreePoolWithTag
    • ExAllocatePool
    • ZwClose
    • MmUnmapLockedPages
    • IoDeleteDevice
    • KeSetEvent
    • MmFreeContiguousMemory
    • MmUnmapIoSpace
    • IoFreeMdl
    • ZwUnmapViewOfSection
    • IoConnectInterrupt
    • IoDisconnectInterrupt
    • IoStartNextPacket
    • KeInsertQueueDpc
    • MmMapLockedPages
    • ZwMapViewOfSection
    • MmBuildMdlForNonPagedPool
    • MmGetPhysicalAddress
    • MmMapLockedPagesSpecifyCache
    • ObReferenceObjectByHandle
    • ZwOpenSection
    • IoAllocateMdl
    • MmAllocateContiguousMemory
    • KeBugCheckEx
    • RtlInitUnicodeString
    • _snwprintf
    • IoCreateNotificationEvent
    • IoDeleteSymbolicLink
    • HalTranslateBusAddress
    • HalGetInterruptVector
    • KeStallExecutionProcessor

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "0400000000012f4ee152d7",
          "Signature": "4e5e56901e46b4d94931f3bb1739281bc216ddfd41dc0905049b6fb2a29ad6992e40990055b5ea3fa52076d38634d417cc553ac782eeefa8babcd8069f1550dfcd167b523a02d7191afdaff0785ce04bc518df3a241edaacb8a95804020730dbb0125efe31bef00448f4f070f83a5e5683cf3dfb0dbcf4c5ed979db9d4dba52784e3389b8ba735864420a43b6da46a0ba183fd28ebdaef28f6cc885dfb0a3b00abe021ebe22f356c0f8e344597eba2f79933357ecb9a8abb454de73f9fc2d98afa65b26ec77e65ffe892e12c31a2f7b02736488f266f3bee4d761f79c3e57f9635bc2d0ecc01b08e7fff518080a792d4b34446648c874f166307314b63b0dff3",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign Timestamping CA , G2",
          "TBS": {
            "MD5": "e140543fe3256027cfa79fc3c19c1776",
            "SHA1": "c655f94eb1ecc93de319fc0c9a2dc6c5ec063728",
            "SHA256": "3ca71e85908ff67368e4dc00253f5691b9e6d50c966e7784143d75fb92aa3448",
            "SHA384": "d9d366f9328f2b55ee19a32cc5fd5148b81d764282fe5dc196c872ae249caa51d2c212ef39f33945dfe0cda81925e326"
          },
          "ValidFrom": "2011-04-13 10:00:00",
          "ValidTo": "2028-01-28 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "0400000000013189c637e8",
          "Signature": "79b06934e20587f6fed4602c2f86793403e0b107930c845cf9e4dc6ccf6eb5ec0a5cba0bd068312e3f64bd0f826b6677817fc629a517d8f0894d832411f66efe9de1480a28a0e27b2480a4ecc29a00d7b06d6ccd88d51578cf13f988a5734dc1362bdccbcedb7e7cd28bef2fbdb34f4d3aadbb626e2893c40ccbd9e6cae011029403b0bd3f942856901e53c227d5c93ccd1a631e825915b640caa781aac355af33d1b575e809ea47084822fb5d1bf32c7a697ec5d75a5e56333cad57e8932542c3d25e713b4a1c54eda955ac2805c7c46c5ddc3c93f6693c8251ce1a153d5e0173ff40a2eab4aed38efaee5d6c47c741f5d45657f2183732d6d4cc4bf671e076",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign CodeSigning CA , SHA256 , G2",
          "TBS": {
            "MD5": "0140a61a07f5dfb1d7d3c66ec7d6a916",
            "SHA1": "38cf80255975d689f1ab266a85bc72335a82e41f",
            "SHA256": "79a79284a0ef2db92bc02b235895de02ee6a15bb7ee233185d4567f9fc3d1d1a",
            "SHA384": "5fcadd07057f8358148fca22ad424498f8e1a97bb55317e4426f809000542988867e0c44d0175950450653e0d20dd83a"
          },
          "ValidFrom": "2011-08-02 10:00:00",
          "ValidTo": "2019-08-02 10:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "04000000000125071df9af",
          "Signature": "4252a97ea2cf5b3bcb4bddbaf85759d324a47772ef62443782ed06ee04d5165f24a314dc6c54056ab09b3dda8139daad28db956f8183f5cd62b14524b1dd29e5085495958cf01d065f1ad6463f1340174811169b474dd13ab50f571c9230d0f8b2253b0acdf687f9c7b257d33f7da58c14ce9ca8c79f4693da59fa795d652035445a4fc1909dc1549256dc34c8f5c103d05dc059489c00fc95a0f1d176f71636c813927f2d2bc0b880f126261f414d52bf1e97bb018208e715f6c1d5342accf5e4c3877a5781e1d6d74286620177e2a9c47a86f404387a076a7d00ec73f7a80b3478c59eb3efb838400e8c3353c875ec5f3eea755eff820e7415dc1905f3ba31",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "OU=GlobalSign Root CA , R3, O=GlobalSign, CN=GlobalSign",
          "TBS": {
            "MD5": "f47739306d14722e670d9436eadb8e4f",
            "SHA1": "457d9df00a652cb4c3356d00145d9528fc309172",
            "SHA256": "bd1765c56594221373893ef26d97f88c144fb0e5a0111215b45d7239c3444df7",
            "SHA384": "b8b268a1bdf388be66a1c969b7b353cb2bbc9fad446049b7efa05a9ab3b714494e97f4d1ee1c0bae35bfd9bf6ef275b3"
          },
          "ValidFrom": "2009-11-18 10:00:00",
          "ValidTo": "2019-03-18 10:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "112106a081d33fd87ae5824cc16b52094e03",
          "Signature": "8032dc078d1ca09c9d3c2ae83d218b59a14d7ecc44ce03be7eaabcc4e67b73bb4bf188da904e7537283863b9d72b0f54a956ce7739973073cd9bd9d905451c8da4b8035d4fd91c2e98e0e988e6ecd7057e562a7bf7165ba3ad8f972512841bb25c634a0ad2ef10544782843569289c0ce41f141624fa75dc74726e4ecae36a43afcf7d3648d1bde906912c2fa6c871fdcfbdd89d2198fcafdbde228cafa7f377ef9ddca3704b441af078851ef2a58c39b5dc881c37edad14f5070b26bdbe6d025eb1b8b0586c853a0df6ff5a270cc5de53e7543c564cc94e4c30f6f25cfb1a8cc282bead5991f61b4d557bcf5b01dcfd7ad36f235c32479b01f3c15114468a9b",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=SG, O=GMO GlobalSign Pte Ltd, CN=GlobalSign TSA for MS Authenticode , G2",
          "TBS": {
            "MD5": "a0ac4d48fe852f7b3ed4e623d59a825f",
            "SHA1": "d4db9846bc4d7db142eeb364286f6de7c102420c",
            "SHA256": "78d2e41a13eb4e9171bae2d2adb192cf39210b5231f77cda936bcfbe8c003bdf",
            "SHA384": "990ed96dca5979deeedc98a012279f04efb5559d7e7f5084a12f3802ee9439326557aecefd081cff739b78515b5d7f50"
          },
          "ValidFrom": "2015-02-03 00:00:00",
          "ValidTo": "2026-03-03 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "11216e054fad930d88cabc078eb0d3bcc8ac",
          "Signature": "386e2be7e95562b52e95ae0e00ab2181b2d671a2d324c96e5512d8af948dd9e15d42aafe5431ae079857b9c35ccd663ba7c0fef04974f27d8bf8a384fd5489393bdacf6dee7067f5ea9f11311e4a1b3b917c866eaee253c8edd08fc79e25bca7e0c0e892d4f0d65cce1aea7e4813c53d8baa708ad6ee167c4b6ba2cf88a6f29661aab4cd73062532812338ca25950c06dc45becdf28ee42048c9cbaa8ec58c8f2afb18b82e0b7ef389417c48900b41e4093c664ab69bbf35fb7af80baefd1781999e6b119ff8bf21245611aa6c2cd356631c67e1dd9c69da25746b7f543014be046ef19b1cf9a5bfd0594d8816f83aa590588e9501166b85ed40961885fb54f7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=MA, L=North Andover, O=eSupport.com, Inc., CN=eSupport.com, Inc.",
          "TBS": {
            "MD5": "07ff655cdba156b39f88d802c992ebf3",
            "SHA1": "3c8d5517e4d30167f270e3543d5e2ce2bf467070",
            "SHA256": "a065dcc26ff157388fbb81ef23454b8eaf2deaa4794040f4bf1afb6a6d79d0a7",
            "SHA384": "e9c4de5f60539f7237e8d371e15b74bcc18d5b329fa6545c422b0c400f98d6c1e482c5a9b98e61c5ab8958c76e226976"
          },
          "ValidFrom": "2014-09-24 20:36:26",
          "ValidTo": "2015-09-25 20:36:26",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "6129152700000000002a",
          "Signature": "5ff8d065746a81c6a6ca5b03b6914ae84bbdef2ba142f0efb4a5adcd3389ec0b9585ac62501108aa58d25aa08310e5a6337af25af2c5fe787cf09c83df190ad97396002dd62ccde914d41d9de83f3c1a76f7904efb01350a6c9313a0c356eb67a0e4d17a96dec267f190f80a7bf5321b94ec5f751f8d1b34da6c58a7cb2d279e2226b7c9aa30cc0777b836e38201b5393ccc8dd9a75f7f23b3877fdb5798918bd7ce2520e39d644fdd87f72b68490318e0a5df7c5f68644d36838d4781f2e9e0a869abfa7b163c05a449ea8830190a6c73055178dfd41ddd3ad47f2de44e54be83431e7a7433b4a4ebd77073bc2a02988966eef6bc8f749378e329025a5a43e258ce7ccf9acad236893be25fda26054ec8d4e72c910e1797c5beee8b13112323294ffa83d050f6bafad53db3173df4ff034aa325dce67561d1fa35086bd62744d068b78d45e0eb852cc8a15d614474160e5958aed2b5eea5bcd6d7076ab62978fd976767dd8d4f17944fd2ed0caf972437c3a29c81da6be143b6577b4cecbf791319e79fe844e94781b75e701e91f83dd17b27f50b7056434805dda92fab86101d0b12e31ad04c6e75ded645b30b748887935c564a41029af7aeb799d8b67f88fa11f2457cf4d71b91c01cf1a0fbd4080a411a142acef4eb34486e66879ed54b7a397fbb0e3d3861cf735706e412066bd96b5308cd7018c22d4f974691bca9f0",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=BE, O=GlobalSign nv,sa, OU=Root CA, CN=GlobalSign Root CA",
          "TBS": {
            "MD5": "0bb058d116f02817737920f112d9fd3b",
            "SHA1": "fd116235171a4feafedee586b7a59185fb5fd7e6",
            "SHA256": "f970426cc46d2ae0fc5f899fa19dbe76e05f07e525654c60c3c9399492c291f4",
            "SHA384": "c0df876be008c26ca407fe904e6f5e7ccded17f9c16830ce9f8022309c9e64c97f494810f152811ae43e223b82ad7cc6"
          },
          "ValidFrom": "2011-04-15 19:55:08",
          "ValidTo": "2021-04-15 20:05:08",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign CodeSigning CA , SHA256 , G2",
          "SerialNumber": "11216e054fad930d88cabc078eb0d3bcc8ac",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    FilenameAgent64.sys
    Creation Timestamp2009-12-14 03:23:26
    MD5ddc2ffe0ab3fcd48db898ab13c38d88d
    SHA133cdab3bbc8b3adce4067a1b042778607dce2acd
    SHA2566948480954137987a0be626c24cf594390960242cd75f094cd6aaa5c2e7a54fa
    Authentihash MD5d86884546c97e614b73d16c600cfb2df
    Authentihash SHA194f7575a6bb378d0cf85b3dc65941c95415e7a80
    Authentihash SHA2563bc0cec99dce687304dad8f7a6daf772e695cbd0169d346d03ae12500361a1e8
    RichPEHeaderHash MD5dd9ea0c6c3773a8caf1a86726551af41
    RichPEHeaderHash SHA145509ef0d417fb2a30496adc9511d048e4730f98
    RichPEHeaderHash SHA2565b467c45ee29fdaba31eff00eacc8db61940f94a9bf6a357c0663c58b2cd752b
    Publisher"eSupport.com, Inc.", Phoenix Technologies Ltd, "eSupport.com, Inc"
    CompanyPhoenix Technologies
    DescriptionDriverAgent Direct I/O for 64-bit Windows
    ProductDriverAgent
    OriginalFilenameAgent64.sys

    Download

    Certificates

    Expand
    Certificate 3825d7faf861af9ef490e726b5d65ad5
    FieldValue
    ToBeSigned (TBS) MD5d6c7684e9aaa508cf268335f83afe040
    ToBeSigned (TBS) SHA118066d20ad92409c567cdfde745279ff71c75226
    ToBeSigned (TBS) SHA256a612fb22ce8be6dab75e47c98508f98496583e79c9c97b936a8caee9ea9f3fff
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services Signer , G2
    ValidFrom2007-06-15 00:00:00
    ValidTo2012-06-14 23:59:59
    Signature50c54bc82480dfe40d24c2de1ab1a102a1a6822d0c831581370a820e2cb05a1761b5d805fe88dbf19191b3561a40a6eb92be3839b07536743a984fe437ba9989ca95421db0b9c7a08d57e0fad5640442354e01d133a217c84daa27c7f2e1864c02384d8378c6fc53e0ebe00687dda4969e5e0c98e2a5bebf8285c360e1dfad28d8c7a54b64dac71b5bbdac3908d53822a1338b2f8a9aebbc07213f44410907b5651c24bc48d34480eba1cfc902b414cf54c716a3805cf9793e5d727d88179e2c43a2ca53ce7d3df62a3ab84f9400a56d0a835df95e53f418b3570f70c3fbf5ad95a00e17dec4168060c90f2b6e8604f1ebf47827d105c5ee345b5eb94932f233
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber3825d7faf861af9ef490e726b5d65ad5
    Version3
    Certificate 47bf1995df8d524643f7db6d480d31a4
    FieldValue
    ToBeSigned (TBS) MD5518d2ea8a21e879c942d504824ac211c
    ToBeSigned (TBS) SHA121ce87d827077e61abddf2beba69fde5432ea031
    ToBeSigned (TBS) SHA2561ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA
    ValidFrom2003-12-04 00:00:00
    ValidTo2013-12-03 23:59:59
    Signature4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber47bf1995df8d524643f7db6d480d31a4
    Version3
    Certificate 040000000001239e0facb3
    FieldValue
    ToBeSigned (TBS) MD55ccf05e4dec10d9d6fe15d8778325272
    ToBeSigned (TBS) SHA179f0a648bd7f1184f86bff43ae47c9ecc3ed3cec
    ToBeSigned (TBS) SHA25633ea31b892ba274a4aefe545de45c42c218b6dff78146655cdea892545c2cccc
    SubjectC=BE, O=GlobalSign nv,sa, OU=Primary Object Publishing CA, CN=GlobalSign Primary Object Publishing CA
    ValidFrom1999-01-28 13:00:00
    ValidTo2017-01-27 12:00:00
    Signatureb578a6a27c04b77fc97f7d6abc71fa293060c2f4621efe7f431e9b6ee2b21f730b85765b7df54e49062fd4fab79140efed6f8d8e138354c52a023d0aa4dc990b7abd772fcc40c18ff3c48c4e72ba107ce6ff642bc7ce6ca7fcd79a7c8e468d01834d423bdb9c3f9f326157d717b0b33666f0b3fd446f8137b1944ea7562589f58ad66d116262795c42900218d39c23fc08e86445b92d7e805b4eafc38a299283781f914134af85c5fd07994e2c5cfec7fd17bb2525314d72b5b5294b489a376f13c7114e4a451e7e2f319cabe852afd6679734885f0e276a6652d15ac7ac302c2038dd2bff3aebce104582a27b1ba12073569b2a93e60451066c1bdc2f899493
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber040000000001239e0facb3
    Version3
    Certificate 010000000001257ee1f400
    FieldValue
    ToBeSigned (TBS) MD5ed0acf60cdd337b9e0a2ab818d7733c6
    ToBeSigned (TBS) SHA1e5a9eb7de851eb17fed066190a6c4e8b13cc908b
    ToBeSigned (TBS) SHA256ddb82ae2aaed1a98b7c6c84378f622064b4e0e3f9b2abb57819eeba31eabee40
    SubjectC=US, ST=MA, L=North Andover, O=Phoenix Technologies Ltd, OU=eSupport, CN=Phoenix Technologies Ltd
    ValidFrom2009-12-11 17:20:45
    ValidTo2010-12-12 17:20:42
    Signaturea7d9a2c70e374ebde881422b81fab976d3182885474a1379d078c736dc5e32157c8b5c667ec3e4bfb078a7f1e90e27be2bad1a41c54e9b53fcdf4f53c55a4a6e1328c147ca683314ae76a64e00d0487ae707f63c1c8524b5245329d368f7cbe263c7982dc73fe20c76921d51ad2a4333baba7443b5f493d42e8a2abcc510371a0a8a6b549cc41484d1da2442ce77e29284e7a6c1c64f2597e2cef45d2e97e1bb74826cab053233cfffed1d55c0c65b6bdefe00c5817dcbe798aa13bb7fb5c909348d5968c7f049f99943fbe0cf8be7e68fee1c6b45b911ecb1e11683a719be94109894e0c39d50530bbb9d0d2db812b78893f9ed0a870f9f6196268ed35ef119
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber010000000001257ee1f400
    Version3
    Certificate 040000000001239e0faf24
    FieldValue
    ToBeSigned (TBS) MD57dd2351a85d3665eeb6720a21f4f7dee
    ToBeSigned (TBS) SHA177838c4d7f36958a581841d28f481d61ce0696ed
    ToBeSigned (TBS) SHA256846725f4b0193468c1079d6127e9e6e420fc6ed66019ed02d732ba644decad57
    SubjectC=BE, O=GlobalSign nv,sa, OU=ObjectSign CA, CN=GlobalSign ObjectSign CA
    ValidFrom2004-01-22 10:00:00
    ValidTo2017-01-27 10:00:00
    Signature1e6af36df48ea922fe7008652ea15dab3330dd6c78fa4beaadc58dec107a6ac55897396b92f391e20ca7281cd15d768e8b077c136fadc43643b3c1bc3159cf1838d8a33bceffca6758bfe0f1ac613ea23b1ebc025b41ac446bf526f3ed5ea865f6ca65a63fcaf577eba5862a582956f8be161040e9d2fc572c636137662539202e0703a036032594bd7ceb7ed3a3c2c57616753092b9ff7641352168d10e5e5c8ec30360e68040fcc05da2546e6e9267a7811287a2a32bdbb74dffe4d5c7e505e6d5f1aefccd661821f33e47c9e59542612c9d2680b20fa83d0ec9a778df6e748c2c46f672e93c646b2855c44b6433cb78541338f0d57106d43e0d0a350ee0b3
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber040000000001239e0faf24
    Version3
    Certificate 610b7f6b000000000019
    FieldValue
    ToBeSigned (TBS) MD54798d55be7663a75649cda4dedc686ef
    ToBeSigned (TBS) SHA10f1ab2937b245d9466ea6f9bf056a5942e3989cf
    ToBeSigned (TBS) SHA256ef14ea05bb066ee9f4188196dd69cd769b283ac4d7555db52f5e76922d3456e1
    SubjectC=BE, O=GlobalSign nv,sa, OU=Root CA, CN=GlobalSign Root CA
    ValidFrom2006-05-23 17:00:51
    ValidTo2016-05-23 17:10:51
    Signature13c56c5e077f3c57ff9b315f3fbd955425c679f92c31034d64694b56d95b976f7cf3f0d024657538639813701613f7a701f1c623e085866c0bf080945a75e87ce41e92b473bfc1b3a7b00bd31884cbcc09a35c9c4f3eb03a9c2d1bc404ef9737966fe5ecbaac6ab3d4e23cdf8b25e7acbc624531dda40a72e41bf8784301ccba3914de5d90aed85acf5eca46815133d5a60e5867d3d8665888169beeb11acaad91138421da9a6e20efda007428bac95ff34d5dc3da25692554ea44bcc39b29331cd63c961f8781c553d72a2733d42e197c08586ddb4e1999a9ea5ff39a9d8c513a5a5cbd2fa908359b54a7db351a521633343aa380046afdb4838cad90cf0c3a6596ec334e1826b849bbeb8192ff134d324b23c733e7b6716b15f69c80e6bcb76cbe41d5033a7133150050743b0e5df996aaed903eab134c809926bc38a5eb0236891db620be83ab10f8199ed76379d4aeb12f6136f94a4ba833c70e7241f9f1b1907eae46efde397b75a0411459041d42bc4788b8130e05fa1df0808dff70c677d84bdc460e231a72d5bfdefeaaae69583cfc5c46e4d5819a8b6e6559771a32a590a6b6649364fd0753c9a0de28ad2a6cc638d181ce98f54019e92c1743a4265fd3443053e41d02baa40a2f16dd7a60275242bbad98372897e4b8d27911e3108c48d5305d0a0c52def588ea8d1a2d67c9f4801484b7850cd16628a5c66f2461
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber610b7f6b000000000019
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • KeInitializeDpc
    • IofCompleteRequest
    • IoCreateSymbolicLink
    • IoCreateDevice
    • IofCallDriver
    • ExFreePoolWithTag
    • ExAllocatePool
    • ZwClose
    • MmUnmapLockedPages
    • IoDeleteDevice
    • KeSetEvent
    • MmFreeContiguousMemory
    • MmUnmapIoSpace
    • IoFreeMdl
    • ZwUnmapViewOfSection
    • IoConnectInterrupt
    • IoDisconnectInterrupt
    • IoStartNextPacket
    • KeInsertQueueDpc
    • MmMapLockedPages
    • ZwMapViewOfSection
    • MmBuildMdlForNonPagedPool
    • MmGetPhysicalAddress
    • MmMapLockedPagesSpecifyCache
    • ObReferenceObjectByHandle
    • ZwOpenSection
    • IoAllocateMdl
    • MmAllocateContiguousMemory
    • KeBugCheckEx
    • RtlInitUnicodeString
    • _snwprintf
    • IoCreateNotificationEvent
    • IoDeleteSymbolicLink
    • HalTranslateBusAddress
    • HalGetInterruptVector
    • KeStallExecutionProcessor

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "0400000000012f4ee152d7",
          "Signature": "4e5e56901e46b4d94931f3bb1739281bc216ddfd41dc0905049b6fb2a29ad6992e40990055b5ea3fa52076d38634d417cc553ac782eeefa8babcd8069f1550dfcd167b523a02d7191afdaff0785ce04bc518df3a241edaacb8a95804020730dbb0125efe31bef00448f4f070f83a5e5683cf3dfb0dbcf4c5ed979db9d4dba52784e3389b8ba735864420a43b6da46a0ba183fd28ebdaef28f6cc885dfb0a3b00abe021ebe22f356c0f8e344597eba2f79933357ecb9a8abb454de73f9fc2d98afa65b26ec77e65ffe892e12c31a2f7b02736488f266f3bee4d761f79c3e57f9635bc2d0ecc01b08e7fff518080a792d4b34446648c874f166307314b63b0dff3",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign Timestamping CA , G2",
          "TBS": {
            "MD5": "e140543fe3256027cfa79fc3c19c1776",
            "SHA1": "c655f94eb1ecc93de319fc0c9a2dc6c5ec063728",
            "SHA256": "3ca71e85908ff67368e4dc00253f5691b9e6d50c966e7784143d75fb92aa3448",
            "SHA384": "d9d366f9328f2b55ee19a32cc5fd5148b81d764282fe5dc196c872ae249caa51d2c212ef39f33945dfe0cda81925e326"
          },
          "ValidFrom": "2011-04-13 10:00:00",
          "ValidTo": "2028-01-28 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "0400000000013189c637e8",
          "Signature": "79b06934e20587f6fed4602c2f86793403e0b107930c845cf9e4dc6ccf6eb5ec0a5cba0bd068312e3f64bd0f826b6677817fc629a517d8f0894d832411f66efe9de1480a28a0e27b2480a4ecc29a00d7b06d6ccd88d51578cf13f988a5734dc1362bdccbcedb7e7cd28bef2fbdb34f4d3aadbb626e2893c40ccbd9e6cae011029403b0bd3f942856901e53c227d5c93ccd1a631e825915b640caa781aac355af33d1b575e809ea47084822fb5d1bf32c7a697ec5d75a5e56333cad57e8932542c3d25e713b4a1c54eda955ac2805c7c46c5ddc3c93f6693c8251ce1a153d5e0173ff40a2eab4aed38efaee5d6c47c741f5d45657f2183732d6d4cc4bf671e076",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign CodeSigning CA , SHA256 , G2",
          "TBS": {
            "MD5": "0140a61a07f5dfb1d7d3c66ec7d6a916",
            "SHA1": "38cf80255975d689f1ab266a85bc72335a82e41f",
            "SHA256": "79a79284a0ef2db92bc02b235895de02ee6a15bb7ee233185d4567f9fc3d1d1a",
            "SHA384": "5fcadd07057f8358148fca22ad424498f8e1a97bb55317e4426f809000542988867e0c44d0175950450653e0d20dd83a"
          },
          "ValidFrom": "2011-08-02 10:00:00",
          "ValidTo": "2019-08-02 10:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "04000000000125071df9af",
          "Signature": "4252a97ea2cf5b3bcb4bddbaf85759d324a47772ef62443782ed06ee04d5165f24a314dc6c54056ab09b3dda8139daad28db956f8183f5cd62b14524b1dd29e5085495958cf01d065f1ad6463f1340174811169b474dd13ab50f571c9230d0f8b2253b0acdf687f9c7b257d33f7da58c14ce9ca8c79f4693da59fa795d652035445a4fc1909dc1549256dc34c8f5c103d05dc059489c00fc95a0f1d176f71636c813927f2d2bc0b880f126261f414d52bf1e97bb018208e715f6c1d5342accf5e4c3877a5781e1d6d74286620177e2a9c47a86f404387a076a7d00ec73f7a80b3478c59eb3efb838400e8c3353c875ec5f3eea755eff820e7415dc1905f3ba31",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "OU=GlobalSign Root CA , R3, O=GlobalSign, CN=GlobalSign",
          "TBS": {
            "MD5": "f47739306d14722e670d9436eadb8e4f",
            "SHA1": "457d9df00a652cb4c3356d00145d9528fc309172",
            "SHA256": "bd1765c56594221373893ef26d97f88c144fb0e5a0111215b45d7239c3444df7",
            "SHA384": "b8b268a1bdf388be66a1c969b7b353cb2bbc9fad446049b7efa05a9ab3b714494e97f4d1ee1c0bae35bfd9bf6ef275b3"
          },
          "ValidFrom": "2009-11-18 10:00:00",
          "ValidTo": "2019-03-18 10:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "112106a081d33fd87ae5824cc16b52094e03",
          "Signature": "8032dc078d1ca09c9d3c2ae83d218b59a14d7ecc44ce03be7eaabcc4e67b73bb4bf188da904e7537283863b9d72b0f54a956ce7739973073cd9bd9d905451c8da4b8035d4fd91c2e98e0e988e6ecd7057e562a7bf7165ba3ad8f972512841bb25c634a0ad2ef10544782843569289c0ce41f141624fa75dc74726e4ecae36a43afcf7d3648d1bde906912c2fa6c871fdcfbdd89d2198fcafdbde228cafa7f377ef9ddca3704b441af078851ef2a58c39b5dc881c37edad14f5070b26bdbe6d025eb1b8b0586c853a0df6ff5a270cc5de53e7543c564cc94e4c30f6f25cfb1a8cc282bead5991f61b4d557bcf5b01dcfd7ad36f235c32479b01f3c15114468a9b",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=SG, O=GMO GlobalSign Pte Ltd, CN=GlobalSign TSA for MS Authenticode , G2",
          "TBS": {
            "MD5": "a0ac4d48fe852f7b3ed4e623d59a825f",
            "SHA1": "d4db9846bc4d7db142eeb364286f6de7c102420c",
            "SHA256": "78d2e41a13eb4e9171bae2d2adb192cf39210b5231f77cda936bcfbe8c003bdf",
            "SHA384": "990ed96dca5979deeedc98a012279f04efb5559d7e7f5084a12f3802ee9439326557aecefd081cff739b78515b5d7f50"
          },
          "ValidFrom": "2015-02-03 00:00:00",
          "ValidTo": "2026-03-03 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "11216e054fad930d88cabc078eb0d3bcc8ac",
          "Signature": "386e2be7e95562b52e95ae0e00ab2181b2d671a2d324c96e5512d8af948dd9e15d42aafe5431ae079857b9c35ccd663ba7c0fef04974f27d8bf8a384fd5489393bdacf6dee7067f5ea9f11311e4a1b3b917c866eaee253c8edd08fc79e25bca7e0c0e892d4f0d65cce1aea7e4813c53d8baa708ad6ee167c4b6ba2cf88a6f29661aab4cd73062532812338ca25950c06dc45becdf28ee42048c9cbaa8ec58c8f2afb18b82e0b7ef389417c48900b41e4093c664ab69bbf35fb7af80baefd1781999e6b119ff8bf21245611aa6c2cd356631c67e1dd9c69da25746b7f543014be046ef19b1cf9a5bfd0594d8816f83aa590588e9501166b85ed40961885fb54f7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=MA, L=North Andover, O=eSupport.com, Inc., CN=eSupport.com, Inc.",
          "TBS": {
            "MD5": "07ff655cdba156b39f88d802c992ebf3",
            "SHA1": "3c8d5517e4d30167f270e3543d5e2ce2bf467070",
            "SHA256": "a065dcc26ff157388fbb81ef23454b8eaf2deaa4794040f4bf1afb6a6d79d0a7",
            "SHA384": "e9c4de5f60539f7237e8d371e15b74bcc18d5b329fa6545c422b0c400f98d6c1e482c5a9b98e61c5ab8958c76e226976"
          },
          "ValidFrom": "2014-09-24 20:36:26",
          "ValidTo": "2015-09-25 20:36:26",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "6129152700000000002a",
          "Signature": "5ff8d065746a81c6a6ca5b03b6914ae84bbdef2ba142f0efb4a5adcd3389ec0b9585ac62501108aa58d25aa08310e5a6337af25af2c5fe787cf09c83df190ad97396002dd62ccde914d41d9de83f3c1a76f7904efb01350a6c9313a0c356eb67a0e4d17a96dec267f190f80a7bf5321b94ec5f751f8d1b34da6c58a7cb2d279e2226b7c9aa30cc0777b836e38201b5393ccc8dd9a75f7f23b3877fdb5798918bd7ce2520e39d644fdd87f72b68490318e0a5df7c5f68644d36838d4781f2e9e0a869abfa7b163c05a449ea8830190a6c73055178dfd41ddd3ad47f2de44e54be83431e7a7433b4a4ebd77073bc2a02988966eef6bc8f749378e329025a5a43e258ce7ccf9acad236893be25fda26054ec8d4e72c910e1797c5beee8b13112323294ffa83d050f6bafad53db3173df4ff034aa325dce67561d1fa35086bd62744d068b78d45e0eb852cc8a15d614474160e5958aed2b5eea5bcd6d7076ab62978fd976767dd8d4f17944fd2ed0caf972437c3a29c81da6be143b6577b4cecbf791319e79fe844e94781b75e701e91f83dd17b27f50b7056434805dda92fab86101d0b12e31ad04c6e75ded645b30b748887935c564a41029af7aeb799d8b67f88fa11f2457cf4d71b91c01cf1a0fbd4080a411a142acef4eb34486e66879ed54b7a397fbb0e3d3861cf735706e412066bd96b5308cd7018c22d4f974691bca9f0",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=BE, O=GlobalSign nv,sa, OU=Root CA, CN=GlobalSign Root CA",
          "TBS": {
            "MD5": "0bb058d116f02817737920f112d9fd3b",
            "SHA1": "fd116235171a4feafedee586b7a59185fb5fd7e6",
            "SHA256": "f970426cc46d2ae0fc5f899fa19dbe76e05f07e525654c60c3c9399492c291f4",
            "SHA384": "c0df876be008c26ca407fe904e6f5e7ccded17f9c16830ce9f8022309c9e64c97f494810f152811ae43e223b82ad7cc6"
          },
          "ValidFrom": "2011-04-15 19:55:08",
          "ValidTo": "2021-04-15 20:05:08",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign CodeSigning CA , SHA256 , G2",
          "SerialNumber": "11216e054fad930d88cabc078eb0d3bcc8ac",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    FilenameAgent64.sys
    Creation Timestamp2009-12-14 03:23:26
    MD529ccff428e5eb70ae429c3da8968e1ec
    SHA121e6c104fe9731c874fab5c9560c929b2857b918
    SHA2568cb62c5d41148de416014f80bd1fd033fd4d2bd504cb05b90eeb6992a382d58f
    Authentihash MD5d86884546c97e614b73d16c600cfb2df
    Authentihash SHA194f7575a6bb378d0cf85b3dc65941c95415e7a80
    Authentihash SHA2563bc0cec99dce687304dad8f7a6daf772e695cbd0169d346d03ae12500361a1e8
    RichPEHeaderHash MD5dd9ea0c6c3773a8caf1a86726551af41
    RichPEHeaderHash SHA145509ef0d417fb2a30496adc9511d048e4730f98
    RichPEHeaderHash SHA2565b467c45ee29fdaba31eff00eacc8db61940f94a9bf6a357c0663c58b2cd752b
    Publisher"eSupport.com, Inc.", Phoenix Technologies Ltd, "eSupport.com, Inc"
    CompanyPhoenix Technologies
    DescriptionDriverAgent Direct I/O for 64-bit Windows
    ProductDriverAgent
    OriginalFilenameAgent64.sys

    Download

    Certificates

    Expand
    Certificate 7e93ebfb7cc64e59ea4b9a77d406fc3b
    FieldValue
    ToBeSigned (TBS) MD5d0785ad36e427c92b19f6826ab1e8020
    ToBeSigned (TBS) SHA1365b7a9c21bd9373e49052c3e7b3e4646ddd4d43
    ToBeSigned (TBS) SHA256c2abb7484da91a658548de089d52436175fdb760a1387d225611dc0613a1e2ff
    SubjectC=US, O=Symantec Corporation, CN=Symantec Time Stamping Services CA , G2
    ValidFrom2012-12-21 00:00:00
    ValidTo2020-12-30 23:59:59
    Signature03099b8f79ef7f5930aaef68b5fae3091dbb4f82065d375fa6529f168dea1c9209446ef56deb587c30e8f9698d23730b126f47a9ae3911f82ab19bb01ac38eeb599600adce0c4db2d031a6085c2a7afce27a1d574ca86518e979406225966ec7c7376a8321088e41eaddd9573f1d7749872a16065ea6386a2212a35119837eb6
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber7e93ebfb7cc64e59ea4b9a77d406fc3b
    Version3
    Certificate 0400000000012f4ee1355c
    FieldValue
    ToBeSigned (TBS) MD5f6a9e8eb8784f3f694b4e353c08a0ff5
    ToBeSigned (TBS) SHA1589a7d4df869395601ba7538a65afae8c4616385
    ToBeSigned (TBS) SHA256cbdc9a0ad785d0c2013211746b42234e18bdc7d54a7a260647badc1c9e712ed4
    SubjectC=BE, O=GlobalSign nv,sa, CN=GlobalSign CodeSigning CA , G2
    ValidFrom2011-04-13 10:00:00
    ValidTo2019-04-13 10:00:00
    Signature225cc5dd3df40b70d8e3f5e7c58e0901bbb196365c5a07adc7a8444951257aae0da4193b929ccfb94226bb3b6c97e7c7ce116d6891da8d6df1534d54388c61f3c8827669be81320b31c36cc99e200a582ff048fe7e4807aad743589473540431a9780d3b8cb070c13d7ed7bd2f2ac3e2f58f0c90dc6ba5c8be685e5d6df878d2be49951e15780891fb34c8be84adbce0c6dd18dbf3caf07bc2143c18b803ba953e211e3f60697a7f6a039e8d4af9f0282c30845eec267242b16dcb64c3128cd6844b67417cb103177809e3ada8b6962da47e80034f88f7c16b5a4615cd2c198bd8709ce52d49886072a8a4195270435edad64603b0680e24ef4af60b2524ef24
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber0400000000012f4ee1355c
    Version3
    Certificate 0ecff438c8febf356e04d86a981b1a50
    FieldValue
    ToBeSigned (TBS) MD5e9d38360b914c8863f6cba3ee58764d3
    ToBeSigned (TBS) SHA14cba8eae47b6bf76f20b3504b98b8f062694a89b
    ToBeSigned (TBS) SHA25688901d86a4cc1f1bb193d08e1fb63d27452e63f83e228c657ab1a92e4ade3976
    SubjectC=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G4
    ValidFrom2012-10-18 00:00:00
    ValidTo2020-12-29 23:59:59
    Signature783bb4912a004cf08f62303778a38427076f18b2de25dca0d49403aa864e259f9a40031cddcee379cb216806dab632b46dbff42c266333e449646d0de6c3670ef705a4356c7c8916c6e9b2dfb2e9dd20c6710fcd9574dcb65cdebd371f4378e678b5cd280420a3aaf14bc48829910e80d111fcdd5c766e4f5e0e4546416e0db0ea389ab13ada097110fc1c79b4807bac69f4fd9cb60c162bf17f5b093d9b5be216ca13816d002e380da8298f2ce1b2f45aa901af159c2c2f491bdb22bbc3fe789451c386b182885df03db451a179332b2e7bb9dc20091371eb6a195bcfe8a530572c89493fb9cf7fc9bf3e226863539abd6974acc51d3c7f92e0c3bc1cd80475
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber0ecff438c8febf356e04d86a981b1a50
    Version3
    Certificate 11213d2f2fb6b9005e295e3c9596b6442513
    FieldValue
    ToBeSigned (TBS) MD5570a8aca88583d09bea3e125d3d7000b
    ToBeSigned (TBS) SHA108661628ab6fc154918e70be1e880d44b5ef6d18
    ToBeSigned (TBS) SHA256a66a20b7e5eccc727d743a53db3d8db58b16a9855cee5188efd74e8d5290beba
    SubjectC=US, ST=Massachusetts, L=North Andover, O=eSupport.com, Inc, CN=eSupport.com, Inc
    ValidFrom2013-08-20 20:02:56
    ValidTo2014-08-21 20:02:56
    Signature8f8cbb4f0adaa90368c533e8ccdfa1cc41e00542eeff2f26535b87723292930e207a18e6738acd604e85995e5c2783dae363ed56452392b15f55db6d5f0054352847ecce83b3b40504a1a1299d608674bbe771bb10bdaac159895d747de333ab565ccb7e153003b958d2c2c5e0646faec117a93625865ca9446d2c8fd6cdd474c4c9d11aa2c6dae281c649564df8918607430a7391144cbc9401aac196acabd2bf077fb25dc2d8a90dde1523dbec77eb72c782b3c7b3b0d4c50915bac1f256ed27e6b73d992927946dae1a8675b9cd0e68ba58c4d609f8b3bb20dfade8f1f436213c2965db77ef07105cbb9daf2ba0f70afd473ee557204bf7caeb7938244f50
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber11213d2f2fb6b9005e295e3c9596b6442513
    Version3
    Certificate 6129152700000000002a
    FieldValue
    ToBeSigned (TBS) MD50bb058d116f02817737920f112d9fd3b
    ToBeSigned (TBS) SHA1fd116235171a4feafedee586b7a59185fb5fd7e6
    ToBeSigned (TBS) SHA256f970426cc46d2ae0fc5f899fa19dbe76e05f07e525654c60c3c9399492c291f4
    SubjectC=BE, O=GlobalSign nv,sa, OU=Root CA, CN=GlobalSign Root CA
    ValidFrom2011-04-15 19:55:08
    ValidTo2021-04-15 20:05:08
    Signature5ff8d065746a81c6a6ca5b03b6914ae84bbdef2ba142f0efb4a5adcd3389ec0b9585ac62501108aa58d25aa08310e5a6337af25af2c5fe787cf09c83df190ad97396002dd62ccde914d41d9de83f3c1a76f7904efb01350a6c9313a0c356eb67a0e4d17a96dec267f190f80a7bf5321b94ec5f751f8d1b34da6c58a7cb2d279e2226b7c9aa30cc0777b836e38201b5393ccc8dd9a75f7f23b3877fdb5798918bd7ce2520e39d644fdd87f72b68490318e0a5df7c5f68644d36838d4781f2e9e0a869abfa7b163c05a449ea8830190a6c73055178dfd41ddd3ad47f2de44e54be83431e7a7433b4a4ebd77073bc2a02988966eef6bc8f749378e329025a5a43e258ce7ccf9acad236893be25fda26054ec8d4e72c910e1797c5beee8b13112323294ffa83d050f6bafad53db3173df4ff034aa325dce67561d1fa35086bd62744d068b78d45e0eb852cc8a15d614474160e5958aed2b5eea5bcd6d7076ab62978fd976767dd8d4f17944fd2ed0caf972437c3a29c81da6be143b6577b4cecbf791319e79fe844e94781b75e701e91f83dd17b27f50b7056434805dda92fab86101d0b12e31ad04c6e75ded645b30b748887935c564a41029af7aeb799d8b67f88fa11f2457cf4d71b91c01cf1a0fbd4080a411a142acef4eb34486e66879ed54b7a397fbb0e3d3861cf735706e412066bd96b5308cd7018c22d4f974691bca9f0
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber6129152700000000002a
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • KeInitializeDpc
    • IofCompleteRequest
    • IoCreateSymbolicLink
    • IoCreateDevice
    • IofCallDriver
    • ExFreePoolWithTag
    • ExAllocatePool
    • ZwClose
    • MmUnmapLockedPages
    • IoDeleteDevice
    • KeSetEvent
    • MmFreeContiguousMemory
    • MmUnmapIoSpace
    • IoFreeMdl
    • ZwUnmapViewOfSection
    • IoConnectInterrupt
    • IoDisconnectInterrupt
    • IoStartNextPacket
    • KeInsertQueueDpc
    • MmMapLockedPages
    • ZwMapViewOfSection
    • MmBuildMdlForNonPagedPool
    • MmGetPhysicalAddress
    • MmMapLockedPagesSpecifyCache
    • ObReferenceObjectByHandle
    • ZwOpenSection
    • IoAllocateMdl
    • MmAllocateContiguousMemory
    • KeBugCheckEx
    • RtlInitUnicodeString
    • _snwprintf
    • IoCreateNotificationEvent
    • IoDeleteSymbolicLink
    • HalTranslateBusAddress
    • HalGetInterruptVector
    • KeStallExecutionProcessor

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "0400000000012f4ee152d7",
          "Signature": "4e5e56901e46b4d94931f3bb1739281bc216ddfd41dc0905049b6fb2a29ad6992e40990055b5ea3fa52076d38634d417cc553ac782eeefa8babcd8069f1550dfcd167b523a02d7191afdaff0785ce04bc518df3a241edaacb8a95804020730dbb0125efe31bef00448f4f070f83a5e5683cf3dfb0dbcf4c5ed979db9d4dba52784e3389b8ba735864420a43b6da46a0ba183fd28ebdaef28f6cc885dfb0a3b00abe021ebe22f356c0f8e344597eba2f79933357ecb9a8abb454de73f9fc2d98afa65b26ec77e65ffe892e12c31a2f7b02736488f266f3bee4d761f79c3e57f9635bc2d0ecc01b08e7fff518080a792d4b34446648c874f166307314b63b0dff3",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign Timestamping CA , G2",
          "TBS": {
            "MD5": "e140543fe3256027cfa79fc3c19c1776",
            "SHA1": "c655f94eb1ecc93de319fc0c9a2dc6c5ec063728",
            "SHA256": "3ca71e85908ff67368e4dc00253f5691b9e6d50c966e7784143d75fb92aa3448",
            "SHA384": "d9d366f9328f2b55ee19a32cc5fd5148b81d764282fe5dc196c872ae249caa51d2c212ef39f33945dfe0cda81925e326"
          },
          "ValidFrom": "2011-04-13 10:00:00",
          "ValidTo": "2028-01-28 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "0400000000013189c637e8",
          "Signature": "79b06934e20587f6fed4602c2f86793403e0b107930c845cf9e4dc6ccf6eb5ec0a5cba0bd068312e3f64bd0f826b6677817fc629a517d8f0894d832411f66efe9de1480a28a0e27b2480a4ecc29a00d7b06d6ccd88d51578cf13f988a5734dc1362bdccbcedb7e7cd28bef2fbdb34f4d3aadbb626e2893c40ccbd9e6cae011029403b0bd3f942856901e53c227d5c93ccd1a631e825915b640caa781aac355af33d1b575e809ea47084822fb5d1bf32c7a697ec5d75a5e56333cad57e8932542c3d25e713b4a1c54eda955ac2805c7c46c5ddc3c93f6693c8251ce1a153d5e0173ff40a2eab4aed38efaee5d6c47c741f5d45657f2183732d6d4cc4bf671e076",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign CodeSigning CA , SHA256 , G2",
          "TBS": {
            "MD5": "0140a61a07f5dfb1d7d3c66ec7d6a916",
            "SHA1": "38cf80255975d689f1ab266a85bc72335a82e41f",
            "SHA256": "79a79284a0ef2db92bc02b235895de02ee6a15bb7ee233185d4567f9fc3d1d1a",
            "SHA384": "5fcadd07057f8358148fca22ad424498f8e1a97bb55317e4426f809000542988867e0c44d0175950450653e0d20dd83a"
          },
          "ValidFrom": "2011-08-02 10:00:00",
          "ValidTo": "2019-08-02 10:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "04000000000125071df9af",
          "Signature": "4252a97ea2cf5b3bcb4bddbaf85759d324a47772ef62443782ed06ee04d5165f24a314dc6c54056ab09b3dda8139daad28db956f8183f5cd62b14524b1dd29e5085495958cf01d065f1ad6463f1340174811169b474dd13ab50f571c9230d0f8b2253b0acdf687f9c7b257d33f7da58c14ce9ca8c79f4693da59fa795d652035445a4fc1909dc1549256dc34c8f5c103d05dc059489c00fc95a0f1d176f71636c813927f2d2bc0b880f126261f414d52bf1e97bb018208e715f6c1d5342accf5e4c3877a5781e1d6d74286620177e2a9c47a86f404387a076a7d00ec73f7a80b3478c59eb3efb838400e8c3353c875ec5f3eea755eff820e7415dc1905f3ba31",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "OU=GlobalSign Root CA , R3, O=GlobalSign, CN=GlobalSign",
          "TBS": {
            "MD5": "f47739306d14722e670d9436eadb8e4f",
            "SHA1": "457d9df00a652cb4c3356d00145d9528fc309172",
            "SHA256": "bd1765c56594221373893ef26d97f88c144fb0e5a0111215b45d7239c3444df7",
            "SHA384": "b8b268a1bdf388be66a1c969b7b353cb2bbc9fad446049b7efa05a9ab3b714494e97f4d1ee1c0bae35bfd9bf6ef275b3"
          },
          "ValidFrom": "2009-11-18 10:00:00",
          "ValidTo": "2019-03-18 10:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "112106a081d33fd87ae5824cc16b52094e03",
          "Signature": "8032dc078d1ca09c9d3c2ae83d218b59a14d7ecc44ce03be7eaabcc4e67b73bb4bf188da904e7537283863b9d72b0f54a956ce7739973073cd9bd9d905451c8da4b8035d4fd91c2e98e0e988e6ecd7057e562a7bf7165ba3ad8f972512841bb25c634a0ad2ef10544782843569289c0ce41f141624fa75dc74726e4ecae36a43afcf7d3648d1bde906912c2fa6c871fdcfbdd89d2198fcafdbde228cafa7f377ef9ddca3704b441af078851ef2a58c39b5dc881c37edad14f5070b26bdbe6d025eb1b8b0586c853a0df6ff5a270cc5de53e7543c564cc94e4c30f6f25cfb1a8cc282bead5991f61b4d557bcf5b01dcfd7ad36f235c32479b01f3c15114468a9b",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=SG, O=GMO GlobalSign Pte Ltd, CN=GlobalSign TSA for MS Authenticode , G2",
          "TBS": {
            "MD5": "a0ac4d48fe852f7b3ed4e623d59a825f",
            "SHA1": "d4db9846bc4d7db142eeb364286f6de7c102420c",
            "SHA256": "78d2e41a13eb4e9171bae2d2adb192cf39210b5231f77cda936bcfbe8c003bdf",
            "SHA384": "990ed96dca5979deeedc98a012279f04efb5559d7e7f5084a12f3802ee9439326557aecefd081cff739b78515b5d7f50"
          },
          "ValidFrom": "2015-02-03 00:00:00",
          "ValidTo": "2026-03-03 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "11216e054fad930d88cabc078eb0d3bcc8ac",
          "Signature": "386e2be7e95562b52e95ae0e00ab2181b2d671a2d324c96e5512d8af948dd9e15d42aafe5431ae079857b9c35ccd663ba7c0fef04974f27d8bf8a384fd5489393bdacf6dee7067f5ea9f11311e4a1b3b917c866eaee253c8edd08fc79e25bca7e0c0e892d4f0d65cce1aea7e4813c53d8baa708ad6ee167c4b6ba2cf88a6f29661aab4cd73062532812338ca25950c06dc45becdf28ee42048c9cbaa8ec58c8f2afb18b82e0b7ef389417c48900b41e4093c664ab69bbf35fb7af80baefd1781999e6b119ff8bf21245611aa6c2cd356631c67e1dd9c69da25746b7f543014be046ef19b1cf9a5bfd0594d8816f83aa590588e9501166b85ed40961885fb54f7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=MA, L=North Andover, O=eSupport.com, Inc., CN=eSupport.com, Inc.",
          "TBS": {
            "MD5": "07ff655cdba156b39f88d802c992ebf3",
            "SHA1": "3c8d5517e4d30167f270e3543d5e2ce2bf467070",
            "SHA256": "a065dcc26ff157388fbb81ef23454b8eaf2deaa4794040f4bf1afb6a6d79d0a7",
            "SHA384": "e9c4de5f60539f7237e8d371e15b74bcc18d5b329fa6545c422b0c400f98d6c1e482c5a9b98e61c5ab8958c76e226976"
          },
          "ValidFrom": "2014-09-24 20:36:26",
          "ValidTo": "2015-09-25 20:36:26",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "6129152700000000002a",
          "Signature": "5ff8d065746a81c6a6ca5b03b6914ae84bbdef2ba142f0efb4a5adcd3389ec0b9585ac62501108aa58d25aa08310e5a6337af25af2c5fe787cf09c83df190ad97396002dd62ccde914d41d9de83f3c1a76f7904efb01350a6c9313a0c356eb67a0e4d17a96dec267f190f80a7bf5321b94ec5f751f8d1b34da6c58a7cb2d279e2226b7c9aa30cc0777b836e38201b5393ccc8dd9a75f7f23b3877fdb5798918bd7ce2520e39d644fdd87f72b68490318e0a5df7c5f68644d36838d4781f2e9e0a869abfa7b163c05a449ea8830190a6c73055178dfd41ddd3ad47f2de44e54be83431e7a7433b4a4ebd77073bc2a02988966eef6bc8f749378e329025a5a43e258ce7ccf9acad236893be25fda26054ec8d4e72c910e1797c5beee8b13112323294ffa83d050f6bafad53db3173df4ff034aa325dce67561d1fa35086bd62744d068b78d45e0eb852cc8a15d614474160e5958aed2b5eea5bcd6d7076ab62978fd976767dd8d4f17944fd2ed0caf972437c3a29c81da6be143b6577b4cecbf791319e79fe844e94781b75e701e91f83dd17b27f50b7056434805dda92fab86101d0b12e31ad04c6e75ded645b30b748887935c564a41029af7aeb799d8b67f88fa11f2457cf4d71b91c01cf1a0fbd4080a411a142acef4eb34486e66879ed54b7a397fbb0e3d3861cf735706e412066bd96b5308cd7018c22d4f974691bca9f0",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=BE, O=GlobalSign nv,sa, OU=Root CA, CN=GlobalSign Root CA",
          "TBS": {
            "MD5": "0bb058d116f02817737920f112d9fd3b",
            "SHA1": "fd116235171a4feafedee586b7a59185fb5fd7e6",
            "SHA256": "f970426cc46d2ae0fc5f899fa19dbe76e05f07e525654c60c3c9399492c291f4",
            "SHA384": "c0df876be008c26ca407fe904e6f5e7ccded17f9c16830ce9f8022309c9e64c97f494810f152811ae43e223b82ad7cc6"
          },
          "ValidFrom": "2011-04-15 19:55:08",
          "ValidTo": "2021-04-15 20:05:08",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign CodeSigning CA , SHA256 , G2",
          "SerialNumber": "11216e054fad930d88cabc078eb0d3bcc8ac",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    FilenameAgent64.sys
    Creation Timestamp2009-12-14 03:23:26
    MD5a57b47489febc552515778dd0fd1e51c
    SHA1d979353d04bf65cc92ad3412605bc81edbb75ec2
    SHA256b1d96233235a62dbb21b8dbe2d1ae333199669f67664b107bff1ad49b41d9414
    Authentihash MD5d86884546c97e614b73d16c600cfb2df
    Authentihash SHA194f7575a6bb378d0cf85b3dc65941c95415e7a80
    Authentihash SHA2563bc0cec99dce687304dad8f7a6daf772e695cbd0169d346d03ae12500361a1e8
    RichPEHeaderHash MD5dd9ea0c6c3773a8caf1a86726551af41
    RichPEHeaderHash SHA145509ef0d417fb2a30496adc9511d048e4730f98
    RichPEHeaderHash SHA2565b467c45ee29fdaba31eff00eacc8db61940f94a9bf6a357c0663c58b2cd752b
    Publisher"eSupport.com, Inc.", Phoenix Technologies Ltd, "eSupport.com, Inc"
    CompanyPhoenix Technologies
    DescriptionDriverAgent Direct I/O for 64-bit Windows
    ProductDriverAgent
    OriginalFilenameAgent64.sys

    Download

    Certificates

    Expand
    Certificate 04000000000125071df9af
    FieldValue
    ToBeSigned (TBS) MD5f47739306d14722e670d9436eadb8e4f
    ToBeSigned (TBS) SHA1457d9df00a652cb4c3356d00145d9528fc309172
    ToBeSigned (TBS) SHA256bd1765c56594221373893ef26d97f88c144fb0e5a0111215b45d7239c3444df7
    SubjectOU=GlobalSign Root CA , R3, O=GlobalSign, CN=GlobalSign
    ValidFrom2009-11-18 10:00:00
    ValidTo2019-03-18 10:00:00
    Signature4252a97ea2cf5b3bcb4bddbaf85759d324a47772ef62443782ed06ee04d5165f24a314dc6c54056ab09b3dda8139daad28db956f8183f5cd62b14524b1dd29e5085495958cf01d065f1ad6463f1340174811169b474dd13ab50f571c9230d0f8b2253b0acdf687f9c7b257d33f7da58c14ce9ca8c79f4693da59fa795d652035445a4fc1909dc1549256dc34c8f5c103d05dc059489c00fc95a0f1d176f71636c813927f2d2bc0b880f126261f414d52bf1e97bb018208e715f6c1d5342accf5e4c3877a5781e1d6d74286620177e2a9c47a86f404387a076a7d00ec73f7a80b3478c59eb3efb838400e8c3353c875ec5f3eea755eff820e7415dc1905f3ba31
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber04000000000125071df9af
    Version3
    Certificate 0400000000013189c64de1
    FieldValue
    ToBeSigned (TBS) MD5b3d3ff804abcd2e7686c126c98cc2c10
    ToBeSigned (TBS) SHA1358391557c2b6213777e282ad8efe9c8112d1b0e
    ToBeSigned (TBS) SHA2569467b8e0d2879abe9a9b791d7a1aa60672949af71bb1b2a5aca1a54368519bca
    SubjectC=BE, O=GlobalSign nv,sa, CN=GlobalSign Extended Validation CodeSigning CA , SHA256 , G2
    ValidFrom2011-08-02 10:00:00
    ValidTo2019-08-02 10:00:00
    Signatureaaa11197ffb423e8f303ecd38eef52a15c833563e5fff142b78335c693f5505e9b8921e85853188834fbdd49e122ea0f8ab122482919dc2ef92368588114552d24b929687853ac72fdcbf18a53a0dac8106f8938236ebb99f17390dbf1bf80a3ae8d4915bc8d88fd591dfe13ae54c3a697cd006b3d4148901505e4a41803d4d7a9e3a940b66c21acd37e1ce65df404b18bda0cd8aaebb936517f173a8d3728c7b7b8719012c66c6cb4843bf1a547dcc4a33b2c5dea0883c4e33910e4ab21650a4256d8b268f693e51ee28301ab0b86b2cfa54a37a4b2dc6cd782318d3f90e6b12a057089fc201d9f2af7ccdd93b5570deb400302d0044f84edf0728007951214
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber0400000000013189c64de1
    Version3
    Certificate 6129152700000000002a
    FieldValue
    ToBeSigned (TBS) MD50bb058d116f02817737920f112d9fd3b
    ToBeSigned (TBS) SHA1fd116235171a4feafedee586b7a59185fb5fd7e6
    ToBeSigned (TBS) SHA256f970426cc46d2ae0fc5f899fa19dbe76e05f07e525654c60c3c9399492c291f4
    SubjectC=BE, O=GlobalSign nv,sa, OU=Root CA, CN=GlobalSign Root CA
    ValidFrom2011-04-15 19:55:08
    ValidTo2021-04-15 20:05:08
    Signature5ff8d065746a81c6a6ca5b03b6914ae84bbdef2ba142f0efb4a5adcd3389ec0b9585ac62501108aa58d25aa08310e5a6337af25af2c5fe787cf09c83df190ad97396002dd62ccde914d41d9de83f3c1a76f7904efb01350a6c9313a0c356eb67a0e4d17a96dec267f190f80a7bf5321b94ec5f751f8d1b34da6c58a7cb2d279e2226b7c9aa30cc0777b836e38201b5393ccc8dd9a75f7f23b3877fdb5798918bd7ce2520e39d644fdd87f72b68490318e0a5df7c5f68644d36838d4781f2e9e0a869abfa7b163c05a449ea8830190a6c73055178dfd41ddd3ad47f2de44e54be83431e7a7433b4a4ebd77073bc2a02988966eef6bc8f749378e329025a5a43e258ce7ccf9acad236893be25fda26054ec8d4e72c910e1797c5beee8b13112323294ffa83d050f6bafad53db3173df4ff034aa325dce67561d1fa35086bd62744d068b78d45e0eb852cc8a15d614474160e5958aed2b5eea5bcd6d7076ab62978fd976767dd8d4f17944fd2ed0caf972437c3a29c81da6be143b6577b4cecbf791319e79fe844e94781b75e701e91f83dd17b27f50b7056434805dda92fab86101d0b12e31ad04c6e75ded645b30b748887935c564a41029af7aeb799d8b67f88fa11f2457cf4d71b91c01cf1a0fbd4080a411a142acef4eb34486e66879ed54b7a397fbb0e3d3861cf735706e412066bd96b5308cd7018c22d4f974691bca9f0
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber6129152700000000002a
    Version3
    Certificate 1121b5d4d579fe52c475c01e3da626487f05
    FieldValue
    ToBeSigned (TBS) MD5f072f16cdf1f6c4bf7cf7e6306bc5fdc
    ToBeSigned (TBS) SHA13cd171c0933a070c0d16bca6ae068aaf4844bb89
    ToBeSigned (TBS) SHA25602243b344c0aafe05d84d4f599fc19d862cd6965a4e0d299af544cbaaea3c58f
    Subject??=Private Organization, serialNumber=001030216, ??=US, ??=Massachusetts, C=US, ST=MA, L=North Andover, ??=120 Water St, O=eSupport.com, Inc., CN=eSupport.com, Inc.
    ValidFrom2015-09-22 15:11:47
    ValidTo2018-09-22 15:11:47
    Signature0918e9fdc6e22f2f347ef860157ccabe11af3d666c186285f58ca1fdf5259e3785834ba138cc84b2f839762b5622053ab7e75610011ba2162b5cf22d083b01cec6f7f6fb900bb3822068e303260f6e82ac8003b64abc3173b3c01c3da9140a19aa6913fbedc0bb9c7a62d5bb3b71126dfa8c3faacf0f08fdf46504cf14cd7711f4abecb3f3b5fc2bd8f05adffccf777319d702d2072a5bcc49b8b78c888bc99e242d822acee354d996cf399c828701f9f5912816c3da6cfb8f3a6837428973fe0d518e645b25037b6861c436994da8543d286772c2d93ebcf3e1773dc8b47043ed278c3dc099c770f74490e0ce16abd3cbf4aaf348b70e2701f759b9cf61a917
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber1121b5d4d579fe52c475c01e3da626487f05
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • KeInitializeDpc
    • IofCompleteRequest
    • IoCreateSymbolicLink
    • IoCreateDevice
    • IofCallDriver
    • ExFreePoolWithTag
    • ExAllocatePool
    • ZwClose
    • MmUnmapLockedPages
    • IoDeleteDevice
    • KeSetEvent
    • MmFreeContiguousMemory
    • MmUnmapIoSpace
    • IoFreeMdl
    • ZwUnmapViewOfSection
    • IoConnectInterrupt
    • IoDisconnectInterrupt
    • IoStartNextPacket
    • KeInsertQueueDpc
    • MmMapLockedPages
    • ZwMapViewOfSection
    • MmBuildMdlForNonPagedPool
    • MmGetPhysicalAddress
    • MmMapLockedPagesSpecifyCache
    • ObReferenceObjectByHandle
    • ZwOpenSection
    • IoAllocateMdl
    • MmAllocateContiguousMemory
    • KeBugCheckEx
    • RtlInitUnicodeString
    • _snwprintf
    • IoCreateNotificationEvent
    • IoDeleteSymbolicLink
    • HalTranslateBusAddress
    • HalGetInterruptVector
    • KeStallExecutionProcessor

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "0400000000012f4ee152d7",
          "Signature": "4e5e56901e46b4d94931f3bb1739281bc216ddfd41dc0905049b6fb2a29ad6992e40990055b5ea3fa52076d38634d417cc553ac782eeefa8babcd8069f1550dfcd167b523a02d7191afdaff0785ce04bc518df3a241edaacb8a95804020730dbb0125efe31bef00448f4f070f83a5e5683cf3dfb0dbcf4c5ed979db9d4dba52784e3389b8ba735864420a43b6da46a0ba183fd28ebdaef28f6cc885dfb0a3b00abe021ebe22f356c0f8e344597eba2f79933357ecb9a8abb454de73f9fc2d98afa65b26ec77e65ffe892e12c31a2f7b02736488f266f3bee4d761f79c3e57f9635bc2d0ecc01b08e7fff518080a792d4b34446648c874f166307314b63b0dff3",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign Timestamping CA , G2",
          "TBS": {
            "MD5": "e140543fe3256027cfa79fc3c19c1776",
            "SHA1": "c655f94eb1ecc93de319fc0c9a2dc6c5ec063728",
            "SHA256": "3ca71e85908ff67368e4dc00253f5691b9e6d50c966e7784143d75fb92aa3448",
            "SHA384": "d9d366f9328f2b55ee19a32cc5fd5148b81d764282fe5dc196c872ae249caa51d2c212ef39f33945dfe0cda81925e326"
          },
          "ValidFrom": "2011-04-13 10:00:00",
          "ValidTo": "2028-01-28 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "0400000000013189c637e8",
          "Signature": "79b06934e20587f6fed4602c2f86793403e0b107930c845cf9e4dc6ccf6eb5ec0a5cba0bd068312e3f64bd0f826b6677817fc629a517d8f0894d832411f66efe9de1480a28a0e27b2480a4ecc29a00d7b06d6ccd88d51578cf13f988a5734dc1362bdccbcedb7e7cd28bef2fbdb34f4d3aadbb626e2893c40ccbd9e6cae011029403b0bd3f942856901e53c227d5c93ccd1a631e825915b640caa781aac355af33d1b575e809ea47084822fb5d1bf32c7a697ec5d75a5e56333cad57e8932542c3d25e713b4a1c54eda955ac2805c7c46c5ddc3c93f6693c8251ce1a153d5e0173ff40a2eab4aed38efaee5d6c47c741f5d45657f2183732d6d4cc4bf671e076",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign CodeSigning CA , SHA256 , G2",
          "TBS": {
            "MD5": "0140a61a07f5dfb1d7d3c66ec7d6a916",
            "SHA1": "38cf80255975d689f1ab266a85bc72335a82e41f",
            "SHA256": "79a79284a0ef2db92bc02b235895de02ee6a15bb7ee233185d4567f9fc3d1d1a",
            "SHA384": "5fcadd07057f8358148fca22ad424498f8e1a97bb55317e4426f809000542988867e0c44d0175950450653e0d20dd83a"
          },
          "ValidFrom": "2011-08-02 10:00:00",
          "ValidTo": "2019-08-02 10:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "04000000000125071df9af",
          "Signature": "4252a97ea2cf5b3bcb4bddbaf85759d324a47772ef62443782ed06ee04d5165f24a314dc6c54056ab09b3dda8139daad28db956f8183f5cd62b14524b1dd29e5085495958cf01d065f1ad6463f1340174811169b474dd13ab50f571c9230d0f8b2253b0acdf687f9c7b257d33f7da58c14ce9ca8c79f4693da59fa795d652035445a4fc1909dc1549256dc34c8f5c103d05dc059489c00fc95a0f1d176f71636c813927f2d2bc0b880f126261f414d52bf1e97bb018208e715f6c1d5342accf5e4c3877a5781e1d6d74286620177e2a9c47a86f404387a076a7d00ec73f7a80b3478c59eb3efb838400e8c3353c875ec5f3eea755eff820e7415dc1905f3ba31",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "OU=GlobalSign Root CA , R3, O=GlobalSign, CN=GlobalSign",
          "TBS": {
            "MD5": "f47739306d14722e670d9436eadb8e4f",
            "SHA1": "457d9df00a652cb4c3356d00145d9528fc309172",
            "SHA256": "bd1765c56594221373893ef26d97f88c144fb0e5a0111215b45d7239c3444df7",
            "SHA384": "b8b268a1bdf388be66a1c969b7b353cb2bbc9fad446049b7efa05a9ab3b714494e97f4d1ee1c0bae35bfd9bf6ef275b3"
          },
          "ValidFrom": "2009-11-18 10:00:00",
          "ValidTo": "2019-03-18 10:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "112106a081d33fd87ae5824cc16b52094e03",
          "Signature": "8032dc078d1ca09c9d3c2ae83d218b59a14d7ecc44ce03be7eaabcc4e67b73bb4bf188da904e7537283863b9d72b0f54a956ce7739973073cd9bd9d905451c8da4b8035d4fd91c2e98e0e988e6ecd7057e562a7bf7165ba3ad8f972512841bb25c634a0ad2ef10544782843569289c0ce41f141624fa75dc74726e4ecae36a43afcf7d3648d1bde906912c2fa6c871fdcfbdd89d2198fcafdbde228cafa7f377ef9ddca3704b441af078851ef2a58c39b5dc881c37edad14f5070b26bdbe6d025eb1b8b0586c853a0df6ff5a270cc5de53e7543c564cc94e4c30f6f25cfb1a8cc282bead5991f61b4d557bcf5b01dcfd7ad36f235c32479b01f3c15114468a9b",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=SG, O=GMO GlobalSign Pte Ltd, CN=GlobalSign TSA for MS Authenticode , G2",
          "TBS": {
            "MD5": "a0ac4d48fe852f7b3ed4e623d59a825f",
            "SHA1": "d4db9846bc4d7db142eeb364286f6de7c102420c",
            "SHA256": "78d2e41a13eb4e9171bae2d2adb192cf39210b5231f77cda936bcfbe8c003bdf",
            "SHA384": "990ed96dca5979deeedc98a012279f04efb5559d7e7f5084a12f3802ee9439326557aecefd081cff739b78515b5d7f50"
          },
          "ValidFrom": "2015-02-03 00:00:00",
          "ValidTo": "2026-03-03 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "11216e054fad930d88cabc078eb0d3bcc8ac",
          "Signature": "386e2be7e95562b52e95ae0e00ab2181b2d671a2d324c96e5512d8af948dd9e15d42aafe5431ae079857b9c35ccd663ba7c0fef04974f27d8bf8a384fd5489393bdacf6dee7067f5ea9f11311e4a1b3b917c866eaee253c8edd08fc79e25bca7e0c0e892d4f0d65cce1aea7e4813c53d8baa708ad6ee167c4b6ba2cf88a6f29661aab4cd73062532812338ca25950c06dc45becdf28ee42048c9cbaa8ec58c8f2afb18b82e0b7ef389417c48900b41e4093c664ab69bbf35fb7af80baefd1781999e6b119ff8bf21245611aa6c2cd356631c67e1dd9c69da25746b7f543014be046ef19b1cf9a5bfd0594d8816f83aa590588e9501166b85ed40961885fb54f7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=MA, L=North Andover, O=eSupport.com, Inc., CN=eSupport.com, Inc.",
          "TBS": {
            "MD5": "07ff655cdba156b39f88d802c992ebf3",
            "SHA1": "3c8d5517e4d30167f270e3543d5e2ce2bf467070",
            "SHA256": "a065dcc26ff157388fbb81ef23454b8eaf2deaa4794040f4bf1afb6a6d79d0a7",
            "SHA384": "e9c4de5f60539f7237e8d371e15b74bcc18d5b329fa6545c422b0c400f98d6c1e482c5a9b98e61c5ab8958c76e226976"
          },
          "ValidFrom": "2014-09-24 20:36:26",
          "ValidTo": "2015-09-25 20:36:26",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "6129152700000000002a",
          "Signature": "5ff8d065746a81c6a6ca5b03b6914ae84bbdef2ba142f0efb4a5adcd3389ec0b9585ac62501108aa58d25aa08310e5a6337af25af2c5fe787cf09c83df190ad97396002dd62ccde914d41d9de83f3c1a76f7904efb01350a6c9313a0c356eb67a0e4d17a96dec267f190f80a7bf5321b94ec5f751f8d1b34da6c58a7cb2d279e2226b7c9aa30cc0777b836e38201b5393ccc8dd9a75f7f23b3877fdb5798918bd7ce2520e39d644fdd87f72b68490318e0a5df7c5f68644d36838d4781f2e9e0a869abfa7b163c05a449ea8830190a6c73055178dfd41ddd3ad47f2de44e54be83431e7a7433b4a4ebd77073bc2a02988966eef6bc8f749378e329025a5a43e258ce7ccf9acad236893be25fda26054ec8d4e72c910e1797c5beee8b13112323294ffa83d050f6bafad53db3173df4ff034aa325dce67561d1fa35086bd62744d068b78d45e0eb852cc8a15d614474160e5958aed2b5eea5bcd6d7076ab62978fd976767dd8d4f17944fd2ed0caf972437c3a29c81da6be143b6577b4cecbf791319e79fe844e94781b75e701e91f83dd17b27f50b7056434805dda92fab86101d0b12e31ad04c6e75ded645b30b748887935c564a41029af7aeb799d8b67f88fa11f2457cf4d71b91c01cf1a0fbd4080a411a142acef4eb34486e66879ed54b7a397fbb0e3d3861cf735706e412066bd96b5308cd7018c22d4f974691bca9f0",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=BE, O=GlobalSign nv,sa, OU=Root CA, CN=GlobalSign Root CA",
          "TBS": {
            "MD5": "0bb058d116f02817737920f112d9fd3b",
            "SHA1": "fd116235171a4feafedee586b7a59185fb5fd7e6",
            "SHA256": "f970426cc46d2ae0fc5f899fa19dbe76e05f07e525654c60c3c9399492c291f4",
            "SHA384": "c0df876be008c26ca407fe904e6f5e7ccded17f9c16830ce9f8022309c9e64c97f494810f152811ae43e223b82ad7cc6"
          },
          "ValidFrom": "2011-04-15 19:55:08",
          "ValidTo": "2021-04-15 20:05:08",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign CodeSigning CA , SHA256 , G2",
          "SerialNumber": "11216e054fad930d88cabc078eb0d3bcc8ac",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filename
    Creation Timestamp2009-12-14 03:23:26
    MD5fe71c99a5830f94d77a8792741d6e6c7
    SHA1acb5d7e182a108ee02c5cb879fc94e0d6db7dd68
    SHA2564db1e0fdc9e6cefeb1d588668ea6161a977c372d841e7b87098cf90aa679abfb
    Authentihash MD5d86884546c97e614b73d16c600cfb2df
    Authentihash SHA194f7575a6bb378d0cf85b3dc65941c95415e7a80
    Authentihash SHA2563bc0cec99dce687304dad8f7a6daf772e695cbd0169d346d03ae12500361a1e8
    RichPEHeaderHash MD5dd9ea0c6c3773a8caf1a86726551af41
    RichPEHeaderHash SHA145509ef0d417fb2a30496adc9511d048e4730f98
    RichPEHeaderHash SHA2565b467c45ee29fdaba31eff00eacc8db61940f94a9bf6a357c0663c58b2cd752b
    CompanyPhoenix Technologies
    DescriptionDriverAgent Direct I/O for 64-bit Windows
    ProductDriverAgent
    OriginalFilenameAgent64.sys

    Download

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • KeInitializeDpc
    • IofCompleteRequest
    • IoCreateSymbolicLink
    • IoCreateDevice
    • IofCallDriver
    • ExFreePoolWithTag
    • ExAllocatePool
    • ZwClose
    • MmUnmapLockedPages
    • IoDeleteDevice
    • KeSetEvent
    • MmFreeContiguousMemory
    • MmUnmapIoSpace
    • IoFreeMdl
    • ZwUnmapViewOfSection
    • IoConnectInterrupt
    • IoDisconnectInterrupt
    • IoStartNextPacket
    • KeInsertQueueDpc
    • MmMapLockedPages
    • ZwMapViewOfSection
    • MmBuildMdlForNonPagedPool
    • MmGetPhysicalAddress
    • MmMapLockedPagesSpecifyCache
    • ObReferenceObjectByHandle
    • ZwOpenSection
    • IoAllocateMdl
    • MmAllocateContiguousMemory
    • KeBugCheckEx
    • RtlInitUnicodeString
    • _snwprintf
    • IoCreateNotificationEvent
    • IoDeleteSymbolicLink
    • HalTranslateBusAddress
    • HalGetInterruptVector
    • KeStallExecutionProcessor

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "0400000000012f4ee152d7",
          "Signature": "4e5e56901e46b4d94931f3bb1739281bc216ddfd41dc0905049b6fb2a29ad6992e40990055b5ea3fa52076d38634d417cc553ac782eeefa8babcd8069f1550dfcd167b523a02d7191afdaff0785ce04bc518df3a241edaacb8a95804020730dbb0125efe31bef00448f4f070f83a5e5683cf3dfb0dbcf4c5ed979db9d4dba52784e3389b8ba735864420a43b6da46a0ba183fd28ebdaef28f6cc885dfb0a3b00abe021ebe22f356c0f8e344597eba2f79933357ecb9a8abb454de73f9fc2d98afa65b26ec77e65ffe892e12c31a2f7b02736488f266f3bee4d761f79c3e57f9635bc2d0ecc01b08e7fff518080a792d4b34446648c874f166307314b63b0dff3",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign Timestamping CA , G2",
          "TBS": {
            "MD5": "e140543fe3256027cfa79fc3c19c1776",
            "SHA1": "c655f94eb1ecc93de319fc0c9a2dc6c5ec063728",
            "SHA256": "3ca71e85908ff67368e4dc00253f5691b9e6d50c966e7784143d75fb92aa3448",
            "SHA384": "d9d366f9328f2b55ee19a32cc5fd5148b81d764282fe5dc196c872ae249caa51d2c212ef39f33945dfe0cda81925e326"
          },
          "ValidFrom": "2011-04-13 10:00:00",
          "ValidTo": "2028-01-28 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "0400000000013189c637e8",
          "Signature": "79b06934e20587f6fed4602c2f86793403e0b107930c845cf9e4dc6ccf6eb5ec0a5cba0bd068312e3f64bd0f826b6677817fc629a517d8f0894d832411f66efe9de1480a28a0e27b2480a4ecc29a00d7b06d6ccd88d51578cf13f988a5734dc1362bdccbcedb7e7cd28bef2fbdb34f4d3aadbb626e2893c40ccbd9e6cae011029403b0bd3f942856901e53c227d5c93ccd1a631e825915b640caa781aac355af33d1b575e809ea47084822fb5d1bf32c7a697ec5d75a5e56333cad57e8932542c3d25e713b4a1c54eda955ac2805c7c46c5ddc3c93f6693c8251ce1a153d5e0173ff40a2eab4aed38efaee5d6c47c741f5d45657f2183732d6d4cc4bf671e076",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign CodeSigning CA , SHA256 , G2",
          "TBS": {
            "MD5": "0140a61a07f5dfb1d7d3c66ec7d6a916",
            "SHA1": "38cf80255975d689f1ab266a85bc72335a82e41f",
            "SHA256": "79a79284a0ef2db92bc02b235895de02ee6a15bb7ee233185d4567f9fc3d1d1a",
            "SHA384": "5fcadd07057f8358148fca22ad424498f8e1a97bb55317e4426f809000542988867e0c44d0175950450653e0d20dd83a"
          },
          "ValidFrom": "2011-08-02 10:00:00",
          "ValidTo": "2019-08-02 10:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "04000000000125071df9af",
          "Signature": "4252a97ea2cf5b3bcb4bddbaf85759d324a47772ef62443782ed06ee04d5165f24a314dc6c54056ab09b3dda8139daad28db956f8183f5cd62b14524b1dd29e5085495958cf01d065f1ad6463f1340174811169b474dd13ab50f571c9230d0f8b2253b0acdf687f9c7b257d33f7da58c14ce9ca8c79f4693da59fa795d652035445a4fc1909dc1549256dc34c8f5c103d05dc059489c00fc95a0f1d176f71636c813927f2d2bc0b880f126261f414d52bf1e97bb018208e715f6c1d5342accf5e4c3877a5781e1d6d74286620177e2a9c47a86f404387a076a7d00ec73f7a80b3478c59eb3efb838400e8c3353c875ec5f3eea755eff820e7415dc1905f3ba31",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "OU=GlobalSign Root CA , R3, O=GlobalSign, CN=GlobalSign",
          "TBS": {
            "MD5": "f47739306d14722e670d9436eadb8e4f",
            "SHA1": "457d9df00a652cb4c3356d00145d9528fc309172",
            "SHA256": "bd1765c56594221373893ef26d97f88c144fb0e5a0111215b45d7239c3444df7",
            "SHA384": "b8b268a1bdf388be66a1c969b7b353cb2bbc9fad446049b7efa05a9ab3b714494e97f4d1ee1c0bae35bfd9bf6ef275b3"
          },
          "ValidFrom": "2009-11-18 10:00:00",
          "ValidTo": "2019-03-18 10:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "112106a081d33fd87ae5824cc16b52094e03",
          "Signature": "8032dc078d1ca09c9d3c2ae83d218b59a14d7ecc44ce03be7eaabcc4e67b73bb4bf188da904e7537283863b9d72b0f54a956ce7739973073cd9bd9d905451c8da4b8035d4fd91c2e98e0e988e6ecd7057e562a7bf7165ba3ad8f972512841bb25c634a0ad2ef10544782843569289c0ce41f141624fa75dc74726e4ecae36a43afcf7d3648d1bde906912c2fa6c871fdcfbdd89d2198fcafdbde228cafa7f377ef9ddca3704b441af078851ef2a58c39b5dc881c37edad14f5070b26bdbe6d025eb1b8b0586c853a0df6ff5a270cc5de53e7543c564cc94e4c30f6f25cfb1a8cc282bead5991f61b4d557bcf5b01dcfd7ad36f235c32479b01f3c15114468a9b",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=SG, O=GMO GlobalSign Pte Ltd, CN=GlobalSign TSA for MS Authenticode , G2",
          "TBS": {
            "MD5": "a0ac4d48fe852f7b3ed4e623d59a825f",
            "SHA1": "d4db9846bc4d7db142eeb364286f6de7c102420c",
            "SHA256": "78d2e41a13eb4e9171bae2d2adb192cf39210b5231f77cda936bcfbe8c003bdf",
            "SHA384": "990ed96dca5979deeedc98a012279f04efb5559d7e7f5084a12f3802ee9439326557aecefd081cff739b78515b5d7f50"
          },
          "ValidFrom": "2015-02-03 00:00:00",
          "ValidTo": "2026-03-03 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "11216e054fad930d88cabc078eb0d3bcc8ac",
          "Signature": "386e2be7e95562b52e95ae0e00ab2181b2d671a2d324c96e5512d8af948dd9e15d42aafe5431ae079857b9c35ccd663ba7c0fef04974f27d8bf8a384fd5489393bdacf6dee7067f5ea9f11311e4a1b3b917c866eaee253c8edd08fc79e25bca7e0c0e892d4f0d65cce1aea7e4813c53d8baa708ad6ee167c4b6ba2cf88a6f29661aab4cd73062532812338ca25950c06dc45becdf28ee42048c9cbaa8ec58c8f2afb18b82e0b7ef389417c48900b41e4093c664ab69bbf35fb7af80baefd1781999e6b119ff8bf21245611aa6c2cd356631c67e1dd9c69da25746b7f543014be046ef19b1cf9a5bfd0594d8816f83aa590588e9501166b85ed40961885fb54f7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, ST=MA, L=North Andover, O=eSupport.com, Inc., CN=eSupport.com, Inc.",
          "TBS": {
            "MD5": "07ff655cdba156b39f88d802c992ebf3",
            "SHA1": "3c8d5517e4d30167f270e3543d5e2ce2bf467070",
            "SHA256": "a065dcc26ff157388fbb81ef23454b8eaf2deaa4794040f4bf1afb6a6d79d0a7",
            "SHA384": "e9c4de5f60539f7237e8d371e15b74bcc18d5b329fa6545c422b0c400f98d6c1e482c5a9b98e61c5ab8958c76e226976"
          },
          "ValidFrom": "2014-09-24 20:36:26",
          "ValidTo": "2015-09-25 20:36:26",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "6129152700000000002a",
          "Signature": "5ff8d065746a81c6a6ca5b03b6914ae84bbdef2ba142f0efb4a5adcd3389ec0b9585ac62501108aa58d25aa08310e5a6337af25af2c5fe787cf09c83df190ad97396002dd62ccde914d41d9de83f3c1a76f7904efb01350a6c9313a0c356eb67a0e4d17a96dec267f190f80a7bf5321b94ec5f751f8d1b34da6c58a7cb2d279e2226b7c9aa30cc0777b836e38201b5393ccc8dd9a75f7f23b3877fdb5798918bd7ce2520e39d644fdd87f72b68490318e0a5df7c5f68644d36838d4781f2e9e0a869abfa7b163c05a449ea8830190a6c73055178dfd41ddd3ad47f2de44e54be83431e7a7433b4a4ebd77073bc2a02988966eef6bc8f749378e329025a5a43e258ce7ccf9acad236893be25fda26054ec8d4e72c910e1797c5beee8b13112323294ffa83d050f6bafad53db3173df4ff034aa325dce67561d1fa35086bd62744d068b78d45e0eb852cc8a15d614474160e5958aed2b5eea5bcd6d7076ab62978fd976767dd8d4f17944fd2ed0caf972437c3a29c81da6be143b6577b4cecbf791319e79fe844e94781b75e701e91f83dd17b27f50b7056434805dda92fab86101d0b12e31ad04c6e75ded645b30b748887935c564a41029af7aeb799d8b67f88fa11f2457cf4d71b91c01cf1a0fbd4080a411a142acef4eb34486e66879ed54b7a397fbb0e3d3861cf735706e412066bd96b5308cd7018c22d4f974691bca9f0",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=BE, O=GlobalSign nv,sa, OU=Root CA, CN=GlobalSign Root CA",
          "TBS": {
            "MD5": "0bb058d116f02817737920f112d9fd3b",
            "SHA1": "fd116235171a4feafedee586b7a59185fb5fd7e6",
            "SHA256": "f970426cc46d2ae0fc5f899fa19dbe76e05f07e525654c60c3c9399492c291f4",
            "SHA384": "c0df876be008c26ca407fe904e6f5e7ccded17f9c16830ce9f8022309c9e64c97f494810f152811ae43e223b82ad7cc6"
          },
          "ValidFrom": "2011-04-15 19:55:08",
          "ValidTo": "2021-04-15 20:05:08",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign CodeSigning CA , SHA256 , G2",
          "SerialNumber": "11216e054fad930d88cabc078eb0d3bcc8ac",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    source

    last_updated: 2024-03-28