enstart_.sys

EnCase Driver

Guidance Software, Inc.

It runs as a Windows kernel mode device driver named “enstart_”.
Publisher:
Guidance Software Inc.  (signed by Guidance Software, Inc.)

Product:
EnCase Driver

Description:
EnCase Driver for WinXP 32 bit Svn Rev:98733 with EnCase 7.9.4.66

MD5:
60b38ed14f35fe0ff8947863e81ec6c5

SHA-1:
fe2253553adc44eedcfc60ae0afe2cc27e9a544d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 2:05:48 AM UTC  (today)

File size:
64.2 KB (65,768 bytes)

Copyright:
© Copyright 2005-present, Guidance Software, Inc. All Rights Reserved

Original file name:
EnPortv.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\enstart_.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/3/2013 5:00:00 PM

Valid to:
3/4/2016 4:59:59 PM

Subject:
CN="Guidance Software, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Guidance Software, Inc.", L=Pasadena, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
44FA8D28C0ED82F6B0BF8DD96943C90C

File PE Metadata
Compilation timestamp:
4/18/2014 2:54:13 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
768:M4XdGLWJE48ECFURqpXKUPGfeTNedkdMUVgJBFRaDKUm1kgThHM7FWyVIjSpg:M+MLWJEFURiaTehedkdZKUCsMMIjP

Entry address:
0xCE3E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 1C, 44, FF, FF, CC, CC, 98, CE, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 46, D3, 00, 00, 0C, 92, 00, 00, 8C, CE, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 70, D3, 00, 00, 00, 92, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 54, D3, 00, 00, 62, D3, 00, 00, 00, 00, 00, 00, F0, CF, 00, 00, 08, D0, 00, 00, 14, D0, 00, 00, 2C, D0, 00, 00, 38, D0, 00, 00, 42, D0, 00, 00, 4C, D0, 00, 00, 68, D0, 00, 00, 7E, D0, 00, 00, 90, D0...
 
[+]

Entropy:
6.3465

Code size:
42.5 KB (43,520 bytes)

Driver
Display name:
enstart_

Type:
Kernel device driver (KernelDriver)


Scan enstart_.sys - Powered by Reason Core Security