driver_bin32

Atsiv

DENWP ATSIV, INC

It runs as a Windows kernel mode device driver named “DRIVER_B”.
Publisher:
Linchpin Labs  (signed by DENWP ATSIV, INC)

Product:
Atsiv

Description:
Windows Device Driver Loader

Version:
1.02

MD5:
94fb1143d74f7a554834c98eaf4d2418

SHA-1:
2e448ea26afa91fa2fe5c415d5bc7a8a28226fbd

SHA-256:
390e22902f874972a1ce1234c778bdd43a198b4b807d4a8c28c5b08ee1e35042

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/26/2024 8:51:42 AM UTC  (today)

Scan engine
Detection
Engine version

Trend Micro House Call
TROJ_GEN.R47H1BR
7.2.222

File size:
20.3 KB (20,792 bytes)

Product version:
1.02

Copyright:
Copyright 2007 Linchpin Labs and OSR

Original file name:
Atsiv.Sys

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\driver_bin32

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/22/2007 7:00:00 PM

Valid to:
4/22/2008 6:59:59 PM

Subject:
CN="DENWP ATSIV, INC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="DENWP ATSIV, INC", L=Las Vegas, S=Nevada, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
77943D7EAF8F90ED416E557706E80A3E

File PE Metadata
Compilation timestamp:
7/31/2007 9:05:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
384:uBHNsG6TK19uzLSFCH36rSbEKuLaylbg6jB1:md6uLwLSFwTbzujbgmX

Entry address:
0x1010

Entry point:
53, 56, 8B, 74, 24, 0C, 57, 8B, 7E, 38, 56, BB, 01, 00, 00, C0, C7, 46, 34, 00, 10, 01, 00, E8, C4, 10, 00, 00, 85, C0, 75, 19, 8B, 44, 24, 14, 8B, 4E, 24, 50, 57, 51, E8, 71, 07, 00, 00, 85, C0, 75, 06, 5F, 5E, 5B, C2, 08, 00, 5F, 5E, 8B, C3, 5B, C2, 08, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 83, EC, 14, 56, 57, 8D, 44, 24, 08, 50, 8D, 4C, 24, 10, 33, FF, 33, F6, 51, 89, 74, 24, 1C, 89, 7C, 24, 14, 89, 7C, 24, 10, E8, 9C, 11, 00, 00, 85, C0, 0F, 85, A2, 00, 00, 00, B8, 49, B4, C2...
 
[+]

Entropy:
6.2274

Code size:
12 KB (12,288 bytes)

Driver
Display name:
DRIVER_B

Type:
Kernel device driver (KernelDriver)


Scan driver_bin32 - Powered by Reason Core Security