evcbt.sys

EVault CBT Driver

EVault

It runs as a Windows 64-bit kernel mode device driver named “EvCbt”.
Publisher:
EVault  (signed and verified)

Product:
EVault CBT Driver

Version:


MD5:
601412d34d1b5dfbcb71167d76539fa3

SHA-1:
b945cdaa821e396a191e91b99a35fa1f5f4d2548

SHA-256:
938bd914787d99122b8e68de554a0de35cf9297953f4f4075d5c28197b388cff

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 2:33:35 PM UTC  (today)

File size:
63.7 KB (65,184 bytes)

Product version:
V1.1.1331

Copyright:
(C)2013-2014 EVault

Original file name:
evcbt.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\evcbt.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/8/2014 7:00:00 PM

Valid to:
1/9/2016 6:59:59 PM

Subject:
CN=EVault, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=EVault, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1C7AF6C77736758FD94AFFF86E6D0FF7

File PE Metadata
Compilation timestamp:
4/6/2015 9:00:24 AM

OS version:
6.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
11.0

CTPH (ssdeep):
768:0d/6fQVLAr2wtUK0k+yTb0tQ5GsWdms8TCMZDUJfOyY+V9eo:RIArDa/yT9mrBFt

Entry address:
0xF070

Entry point:
48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8B, DA, 48, 8B, F9, E8, 83, FF, FF, FF, 48, 8B, D3, 48, 8B, CF, 48, 8B, 5C, 24, 30, 48, 83, C4, 20, 5F, E9, E6, 8C, FF, FF, CC, CC, C8, F0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 16, F8, 00, 00, 00, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B0, F2, 00, 00, 00, 00, 00, 00, D2, F2, 00, 00, 00, 00, 00, 00, F4, F2, 00, 00, 00, 00, 00, 00, 0C, F3, 00, 00, 00, 00, 00, 00, 20, F3, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.7238

Code size:
46.5 KB (47,616 bytes)

Driver
Display name:
EvCbt

Description:
EVault CBT Volume Filter Driver

Type:
Kernel device driver (KernelDriver)

Group:
Filter


Scan evcbt.sys - Powered by Reason Core Security