cmfd.sys

Comodo CP, Inc

It runs as a Windows 64-bit kernel mode device driver named “cmfd”.
Publisher:
Comodo CP, Inc  (signed and verified)

MD5:
d51b3ee5011b0780ebf9a6e6a8b4d572

SHA-1:
959a14b1abf21bdec34e99b883b142341abaab25

SHA-256:
3e173eb82011f7389e1fd556f4e787a6e7b357be5e06779dc422cde016182e1f

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/27/2024 2:52:12 AM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
BC.Heuristics.Rootkit.B-9.SL5IT
0.98/17411

File size:
11.5 KB (11,768 bytes)

File type:
Driver (Win64 SYS)

Common path:
C:\Program Files\comodo\memory firewall\cmfd.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/5/2007 11:00:00 AM

Valid to:
4/5/2008 10:59:59 AM

Subject:
CN="Comodo CP, Inc", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Comodo CP, Inc", S=NewJersey, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5E93B43C900815BF50B6C68DBA2D9FDB

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
192:xwF97afyowJL/aMjGwP7lM9Lbf+ebMfZgjlRM:M7afYJLWdHRbW6j

Entry point:
56, 57, 8B, 7C, 24, 0C, 68, 2C, 30, 00, 10, 6A, 00, 6A, 00, 6A, 22, 6A, 00, 6A, 00, 57, FF, 15, 58, 20, 00, 10, 8B, F0, 85, F6, 7C, 2B, 68, 20, 13, 00, 10, FF, 15, 08, 20, 00, 10, 8B, F0, 85, F6, 7C, 0E, C7, 47, 34, F0, 13, 00, 10, 5F, 33, C0, 5E, C2, 08, 00, A1, 2C, 30, 00, 10, 50, FF, 15, 10, 20, 00, 10, 5F, 8B, C6, 5E, C2, 08, 00, FF, 25, 34, 20, 00, 10, FF, 25, 60, 20, 00, 10, FF, 25, 70, 20, 00, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Driver
Display name:
cmfd

Description:
CMF driver-injector

Type:
Kernel device driver (KernelDriver)


Scan cmfd.sys - Powered by Reason Core Security