BEFlt.sys

SafeGuard Device Encryption

Utimaco Safeware AG

It runs as a Windows kernel mode device driver named “BeFlt”.
Publisher:
Utimaco Safeware AG - a member of the Sophos Group  (signed by Utimaco Safeware AG)

Product:
SafeGuard(R) Device Encryption

Description:
Device Encryption Filter

Version:
5.50.1.13

MD5:
f3c9fe3e3d292975745346d8653c6584

SHA-1:
606669b6357906889e29981de046982f6ac26dfa

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 11:09:00 PM UTC  (a few moments ago)

File size:
92.8 KB (94,976 bytes)

Product version:
5.50.1.13

Copyright:
Copyright © 1996 - 2010 Sophos Group and Utimaco Safeware AG. All rights reserved.

Original file name:
BEFlt.sys

File type:
Driver (Win32 SYS)

Language:
German (Germany)

Common path:
C:\Windows\System32\drivers\beflt.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/7/2009 8:00:00 PM

Valid to:
9/18/2010 7:59:59 PM

Subject:
CN=Utimaco Safeware AG, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Utimaco Safeware AG, L=Oberursel, S=Hessen, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7F579061F1D2D3184491CA140FBF7873

File PE Metadata
Compilation timestamp:
8/5/2010 11:35:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
1536:WzORmuuPyYusJNmFR02+NmgAARTCgXVCAvudSxFIFYd9dxFrJG7nIWEQCDsDL:WzNJSFR02+HAAMgXV9CSxaFM9G7n/f

Entry address:
0x16000

Entry point:
A1, D4, 30, 02, 00, 0F, BF, 08, 53, 55, 56, 8B, 35, 80, 31, 02, 00, 33, ED, 55, 6A, 07, 89, 0D, C8, 47, 02, 00, FF, D6, 84, C0, 8D, 5D, 01, 74, 06, 66, B8, 10, 00, EB, 38, 55, 6A, 06, FF, D6, 84, C0, 74, 06, 66, B8, 08, 00, EB, 29, 6A, 30, 53, FF, D6, 84, C0, 74, 06, 66, B8, 04, 00, EB, 1A, 6A, 20, 53, FF, D6, 84, C0, 74, 06, 66, B8, 02, 00, EB, 0B, 6A, 10, 53, FF, D6, F6, D8, 1B, C0, F7, D8, A8, 08, 8B, 0D, C8, 47, 02, 00, 66, A3, CC, 47, 02, 00, 74, 0E, 81, F9, 58, 1B, 00, 00, 72, 06, 66, B8, 10, 00, EB...
 
[+]

Entropy:
6.4621

Code size:
75.5 KB (77,312 bytes)

Driver
Display name:
BeFlt

Type:
Kernel device driver (KernelDriver)

Group:
Filter


Scan BEFlt.sys - Powered by Reason Core Security