cerber.sys

Windows Win 7 DDK driver

Mega HighTech SL

It runs as a Windows file system device driver named “cerber”.
Publisher:
Windows (R) Win 7 DDK provider  (signed by Mega HighTech SL)

Product:
Windows (R) Win 7 DDK driver

Description:
Scanner Filter

Version:
6.1.7600.16385 built by: WinDDK

MD5:
f8047996a598ce70fc100b96c733f92d

SHA-1:
5594c09b8a05b6e661838195b98be9da6029c433

SHA-256:
33b3d478fd013c70f97f8e8cf2f465a57f577c4ffc30b58b81e794251e2e0f8e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
10/18/2018 5:24:39 PM UTC  (today)

File size:
16.2 KB (16,552 bytes)

Product version:
6.1.7600.16385

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
scanner.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\cerber.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/25/2012 5:30:00 AM

Valid to:
5/26/2013 5:29:59 AM

Subject:
CN=Mega HighTech SL, OU=Cerber Antivirus Labs, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Mega HighTech SL, L=Marbella, S=Malaga, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5F9325FBB30143946B01AA3484C2FCCC

File PE Metadata
Compilation timestamp:
6/7/2012 5:48:17 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
192:USbnT8JNj+i5lNUK1Zvni8Lk8Whv8Za335/wJirNmL/QBrrUe+vAdtbjtlAur9ZE:3P8H+SDkhv8g3mirILQlUKdt3UHeM2K

Entry address:
0x19D5

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, AB, FE, FF, FF, CC, CC, CC, 94, 1A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 8C, 1B, 00, 00, DC, 11, 00, 00, 8C, 1A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, AE, 1B, 00, 00, D4, 11, 00, 00, 38, 1A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B6, 1D, 00, 00, 80, 11, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 18, 1C, 00, 00, 9A, 1D, 00, 00, 82, 1D, 00, 00, 70, 1D, 00, 00, 54, 1D, 00, 00, 38, 1D, 00, 00, 1A, 1D, 00, 00, FA...
 
[+]

Entropy:
6.5938

Code size:
5.5 KB (5,632 bytes)

Driver
Display name:
cerber

Description:
cerber mini-filter driver

Type:
File system 'filter' driver (FileSystemDriver)

Group:
FSFilter Content Screener

Depends on:
FltMgr


Scan cerber.sys - Powered by Reason Core Security