cssdlp.sys

Endpoint Protector

CoSoSys SRL

It runs as a Windows file system device driver named “cssdlp”.
Publisher:
CoSoSys Ltd.  (signed by CoSoSys SRL)

Product:
Endpoint Protector

Description:
Endpoint Protector Mini Filter Driver

Version:
3.00 built by: WinDDK

MD5:
a7659a5a7a22886c8f96659ad300d98f

SHA-1:
47e08fae299947d535ecda1e46a1480ab6e1ad56

SHA-256:
5f55c41f4269e68f49d77fefda19a170edf86b24add182ec0a37218e2beda4cd

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 9:37:00 PM UTC  (today)

File size:
20.4 KB (20,920 bytes)

Product version:
3.00

Copyright:
© CoSoSys Ltd. All rights reserved.

Original file name:
cssdlp.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\cssdlp.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/23/2011 12:49:07 PM

Valid to:
4/2/2013 4:05:33 PM

Subject:
E=info@cososys.com, CN=CoSoSys SRL, OU=Code Siging, O=CoSoSys SRL, L=Cluj-Napoca, S=Cluj, C=RO

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012E5288B564

File PE Metadata
Compilation timestamp:
11/13/2012 11:23:16 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
384:i914IEtrn6EaMrJe/H2gIKz7jPKYYuNE5478ldUb+A:i3M6krI/H2gLz77KYViA

Entry address:
0x513D

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, B9, FE, FF, FF, CC, CC, CC, FC, 51, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, C4, 54, 00, 00, 5C, 20, 00, 00, F4, 51, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, F2, 54, 00, 00, 54, 20, 00, 00, A0, 51, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, D4, 56, 00, 00, 00, 20, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, AA, 56, 00, 00, 92, 56, 00, 00, 7E, 56, 00, 00, 62, 56, 00, 00, 4C, 56, 00, 00, 36, 56, 00, 00, 1C, 56, 00, 00, 06...
 
[+]

Code size:
9 KB (9,216 bytes)

Driver
Display name:
cssdlp

Description:
CssDlp Mini Filter

Type:
File system 'filter' driver (FileSystemDriver)

Group:
FSFilter Activity Monitor

Depends on:
FltMgr


Scan cssdlp.sys - Powered by Reason Core Security