cgwfiltr_wlhx64.sys

Change Guardian for Windows

NetIQ Corporation

Publisher:
NetIQ Corp.   (signed by NetIQ Corporation)

Product:
Change Guardian for Windows

Description:
NetIQ Filter Driver for WinLH (x64)

Version:
2.0.5.8

MD5:
3f19857acb9cf154c37e665c8cfec616

SHA-1:
e65574a91da410628bf68b14d85dd8f748ec830f

SHA-256:
8dc5f58676d9bc1444f7ee368348eb615b3a8b5c574a37f354f7bbc514fdd63c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/4/2025 12:31:52 AM UTC  (today)

File size:
81 KB (82,984 bytes)

Product version:
2.0.5.8

Copyright:
© 1998-2011 NetIQ Corp. All rights reserved.

Original file name:
cgwfiltr.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Program Files\netiq security manager\onepoint\providers\chnctsec\changeguardianprovider\cgwfiltr_wlhx64.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/11/2010 8:00:00 PM

Valid to:
8/22/2013 7:59:59 PM

Subject:
CN=NetIQ Corporation, OU=Digital ID Class 3 - Microsoft VBA Software Validation v2, O=NetIQ Corporation, L=Houston, S=Texas, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2483CBA05CB5FC0E2166B25014D18654

File PE Metadata
Compilation timestamp:
8/18/2011 10:55:02 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
1536:2QqtqQ1F5ZvPOQt0MpVo/B1yGc0BCBnRIt6yX9tg3CTbD+:tQ1Ffnc/KGc0BmCoO9lb6

Entry address:
0x15064

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, 52, C4, FE, FF, CC, CC, B0, 50, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, D2, 59, 01, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 78, 53, 01, 00, 00, 00, 00, 00, 90, 53, 01, 00, 00, 00, 00, 00, AC, 53, 01, 00, 00, 00, 00, 00, C0, 53, 01, 00, 00, 00, 00, 00, D2, 53, 01, 00, 00, 00, 00, 00, F4, 53, 01, 00, 00, 00, 00, 00, 08, 54, 01, 00...
 
[+]

Entropy:
6.1951

Code size:
62 KB (63,488 bytes)

Scan cgwfiltr_wlhx64.sys - Powered by Reason Core Security