avtsafe.sys

QianYun Network Technology(shenzhen) Co., Ltd.

It runs as a Windows kernel mode device driver named “AvtSafe”.
Publisher:
sucop.com  (signed by QianYun Network Technology(shenzhen) Co., Ltd.)

Description:
Sucop Anti-Virus Safe

Version:
1.0.0.5

MD5:
37eeb3955a9e10266fd4d97e58f5be1a

SHA-1:
9a943e76e4d059c9827095e68550baf3acd5dbe1

SHA-256:
1feee890b99558a28e522b9c37e17fce582dacfd8bfc3c766924108684cdad71

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 1:28:49 AM UTC  (today)

File size:
45.2 KB (46,312 bytes)

Product version:
1.0.0.5

Copyright:
Copyright (C) 2006-2011 sucop.com

Original file name:
avtsafe.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Program Files\sucop\avt\avtsafe.sys

Digital Signature
Authority:
Thawte, Inc.

Valid from:
3/2/2011 8:00:00 AM

Valid to:
3/2/2013 7:59:59 AM

Subject:
CN="QianYun Network Technology(shenzhen) Co., Ltd.", OU=Sucop, O="QianYun Network Technology(shenzhen) Co., Ltd.", L=Shenzhen, S=Guangdong, C=CN

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1609B871B1C41D1439AF6E195B3593C0

File PE Metadata
Compilation timestamp:
11/22/2011 6:50:10 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.10

CTPH (ssdeep):
384:eNjupEW1e2gBfXwC+NK7+g5wgFkFqPVKc7Bcx9Yo0PsiM1YJLuu24:mK6NXThBmFqPVKULLE4

Entry address:
0x9385

Entry point:
8B, FF, 55, 8B, EC, A1, B4, 51, 01, 00, 85, C0, B9, 40, BB, 00, 00, 74, 04, 3B, C1, 75, 23, 8B, 15, 30, 3F, 01, 00, B8, B4, 51, 01, 00, C1, E8, 08, 33, 02, 25, FF, FF, 00, 00, A3, B4, 51, 01, 00, 75, 07, 8B, C1, A3, B4, 51, 01, 00, F7, D0, A3, B0, 51, 01, 00, 5D, E9, 3A, 71, FF, FF, 14, 94, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 70, 98, 00, 00, 8C, 3E, 00, 00, 08, 94, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, A6, 98, 00, 00, 80, 3E, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.4313

Code size:
15.9 KB (16,256 bytes)

Driver
Display name:
AvtSafe

Type:
Kernel device driver (KernelDriver)


Scan avtsafe.sys - Powered by Reason Core Security