DksHdd.sys

PC-Wächter

Dr. Kaiser Systemhaus GmbH

It runs as a Windows 64-bit kernel mode device driver named “DKS Disk Filter Driver”.
Publisher:
Dr. Kaiser Systemhaus GmbH  (signed and verified)

Product:
PC-Wächter ®

Description:
Disk Filter Driver

Version:
7, 2, 34, 0

MD5:
e1420125344ecbfd1a891786d3295496

SHA-1:
3960f19be78ace2d5bcc066c3083fdbeb2ad0b99

SHA-256:
8969f7fc8bf895799df9e9284d3f1e8ddf952f673fec0c74459fb0c0ad1329f6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 4:56:33 AM UTC  (today)

File size:
94.6 KB (96,880 bytes)

Product version:
7, 2, 0, 0

Copyright:
© 2000-12 Dr. Kaiser Systemhaus GmbH

Original file name:
DksHdd.sys

File type:
Driver (Win64 SYS)

Language:
German (Germany)

Common path:
C:\Windows\System32\drivers\dkshdd.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/4/2011 6:33:31 PM

Valid to:
7/4/2014 6:33:31 PM

Subject:
E=info@dr-kaiser.de, CN=Dr. Kaiser Systemhaus GmbH, O=Dr. Kaiser Systemhaus GmbH, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11217D93FFCFBBC5050AD0B0A8AC4C8AD3F1

File PE Metadata
Compilation timestamp:
3/1/2013 4:19:43 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
7.10

Entry address:
0x14920

Entry point:
48, 8B, C4, 48, 81, EC, E8, 00, 00, 00, 48, 89, 58, 08, 48, 89, 70, 18, 48, 89, 78, 20, 48, 8B, FA, 48, 8B, F1, E8, 8F, 98, FF, FF, 44, 8B, C0, 8B, D8, 41, 81, E0, 00, 00, 00, C0, 41, 81, F8, 00, 00, 00, C0, 75, 0A, E8, 75, 97, FF, FF, E9, 4E, 01, 00, 00, C7, 44, 24, 30, 40, 00, 00, 00, 48, 89, AC, 24, F8, 00, 00, 00, 33, ED, 4C, 8D, 05, 57, 01, 00, 00, 48, 8D, 8C, 24, 90, 00, 00, 00, 8D, 55, 02, 45, 33, C9, C7, 44, 24, 28, 19, 00, 02, 00, 89, 6C, 24, 20, E8, 68, FA, FF, FF, C7, 44, 24, 30, 40, 00, 00, 00...
 
[+]

Code size:
79.6 KB (81,536 bytes)

Driver
Display name:
DKS Disk Filter Driver

Service name:
DksHdd

Type:
Kernel device driver (KernelDriver)


Scan DksHdd.sys - Powered by Reason Core Security