dcpp2k.sys

DriveCrypt Plus Pack

SecurStar GmbH

It runs as a Windows kernel mode device driver named “dcpp2k”.
Publisher:
SecurStar GmbH  (signed and verified)

Product:
DriveCrypt Plus Pack

Description:
DriveCrypt Plus Pack Kernel Driver

Version:
1, 0, 0, 1

MD5:
b8c2e74f8397d11f5e822915d9d89f41

SHA-1:
9678a128861c66f3b36510852f91ad9924bc2621

SHA-256:
1880b2622234da8fe4b588128f8f3ada6757d84da76d90822a4404613e7ec580

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/26/2024 9:38:32 PM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
PUA.Packed.Armadillo
0.98/17211

File size:
1.6 MB (1,668,592 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright © 2002 SecurStar GmbH

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\dcpp2k.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
4/13/2007 12:29:04 PM

Valid to:
4/13/2010 12:29:04 PM

Subject:
E=contact@securstar.com, CN=SecurStar GmbH, O=SecurStar GmbH, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
01000000000111EA7D2E62

File PE Metadata
Compilation timestamp:
1/19/2010 3:19:06 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
24576:b+9xUygKOibwDGNtrDTrNBzHIDKaZtMovJSVKjdTmZl2msUsb00vNzYCw5dLZtLQ:MPTDDTTzEZJkbZ03vNzYCw5dLM

Entry address:
0x197000

Entry point:
55, 8B, EC, 83, E4, F8, 83, EC, 4C, 53, 33, DB, 56, 8B, 75, 08, 57, 89, 1D, 0C, 47, 1A, 00, 89, 1D, 10, 47, 1A, 00, 89, 1D, 14, 47, 1A, 00, 89, 1D, 18, 47, 1A, 00, 89, 1D, 1C, 47, 1A, 00, 89, 1D, 20, 47, 1A, 00, 89, 1D, 24, 47, 1A, 00, 89, 1D, 28, 47, 1A, 00, 8B, 46, 18, 6A, 01, 89, 5C, 24, 10, C7, 40, 04, E0, 35, 01, 00, 68, 60, 57, 1A, 00, 89, 35, A0, 5B, 1A, 00, 89, 1D, D8, 46, 1A, 00, 89, 1D, 84, 57, 1A, 00, FF, 15, A4, 10, 01, 00, 68, FF, FF, FF, 7F, 53, 68, C0, 47, 1A, 00, FF, 15, 78, 10, 01, 00, B8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
50.5 KB (51,712 bytes)

Driver
Display name:
dcpp2k

Type:
Kernel device driver (KernelDriver)

Group:
PnP Filter


Scan dcpp2k.sys - Powered by Reason Core Security