dvdfabio.sys

DVDFab Virtual Drive

Fengtao Software Inc.

It runs as a Windows kernel mode device driver named “dvdfabio”.
Publisher:
DVDFab Software  (signed by Fengtao Software Inc.)

Product:
DVDFab Virtual Drive

Description:
DVDFabIO Device Driver

Version:
1.5.1.1

MD5:
12c15ad5fa35b27937e5900aefbaf8c5

SHA-1:
cf4949b76ac4dbee09c197809e721d84f5e48576

SHA-256:
77cff367501bbaa30de8f80b7d10f0fd174d3a1f82c9157e8fe7a76852f991a1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/5/2024 1:28:52 AM UTC  (today)

File size:
11.9 KB (12,136 bytes)

Product version:
1.5.1.1

Copyright:
Copyright (C) 2014 Fengtao Software

Original file name:
dvdfabio.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\dvdfabio.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
9/14/2015 1:09:45 PM

Valid to:
8/4/2018 11:16:57 AM

Subject:
CN=Fengtao Software Inc., O=Fengtao Software Inc., L=Beijing, S=Beijing, C=CN

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E2B067DC6C4CC14498C65561316A9EAC

File PE Metadata
Compilation timestamp:
8/29/2014 5:57:33 PM

OS version:
5.2

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
10.0

CTPH (ssdeep):
192:dJpGvUyfdznwpnVTgBxe1HCjWe+PjPKl0iDSCsxxmnU8y:gU4dzYn2KtPLK5WJYn9y

Entry address:
0x3034

Entry point:
8B, FF, 55, 8B, EC, E8, C2, FF, FF, FF, 5D, E9, 36, E4, FF, FF, 6C, 30, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 48, 31, 00, 00, 00, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 9C, 30, 00, 00, B2, 30, 00, 00, C2, 30, 00, 00, DA, 30, 00, 00, E8, 30, 00, 00, F4, 30, 00, 00, 06, 31, 00, 00, 1E, 31, 00, 00, 36, 31, 00, 00, 56, 31, 00, 00, 64, 31, 00, 00, 00, 00, 00, 00, E3, 01, 49, 6F, 66, 43, 6F, 6D, 70, 6C, 65, 74, 65, 52, 65, 71, 75, 65, 73, 74, 00, 00, 10, 05...
 
[+]

Entropy:
6.3470

Code size:
2 KB (2,048 bytes)

Driver
Display name:
dvdfabio

Type:
Kernel device driver (KernelDriver)


Scan dvdfabio.sys - Powered by Reason Core Security