fild.Sys

Filter Driver for DAmo Volume Encryt Products

Penta Security Systems

It runs as a Windows kernel mode device driver named “fild”.
Publisher:
Penta Security Systems  (signed and verified)

Product:
Filter Driver for DAmo Volume Encryt Products

Description:
Driver for DAmo VL-DSK

Version:
1.0.0 2015.06.29

MD5:
90ea4f870da7abd382fc782cd2f868d1

SHA-1:
ffb66a08588674e47edc35ca37c8d6b20f3ab86a

SHA-256:
8862e6289a5b555c9e32bb624965bb5a3a687f81e1c5293caf7275b8f05f161b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/30/2024 4:58:36 AM UTC  (today)

File size:
25.9 KB (26,496 bytes)

Product version:
1.0.0 2015.06.29

Copyright:
Copyright (C) Penta Security Systems 1997-2015

Original file name:
fild.Sys

File type:
Driver (Win32 SYS)

Common path:
C:\Program Files\penta security systems\d'amo ke\fild.sys

Digital Signature
Authority:
Thawte, Inc.

Valid from:
6/19/2015 9:00:00 AM

Valid to:
6/19/2016 8:59:59 AM

Subject:
CN=Penta Security Systems, OU=IT Team, O=Penta Security Systems, L=Yeongdeungpo-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
4EA8A2AC098AA36DB0474E2C666CE1E3

File PE Metadata
Compilation timestamp:
6/29/2015 10:01:45 PM

OS version:
6.3

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
12.0

CTPH (ssdeep):
384:UdF+ag6Dfi57qPmzg361tvdIuLzDZFf/K+ttoAnAuSPLx8GNp:UdF+ag65ag3oNdZfTroAHGn

Entry address:
0x721A

Entry point:
8B, FF, 55, 8B, EC, E8, 06, 00, 00, 00, 5D, E9, D6, FD, FF, FF, 8B, FF, 55, 8B, EC, 51, 51, A1, 34, 50, 40, 00, B9, 4E, E6, 40, BB, 85, C0, 74, 04, 3B, C1, 75, 18, 0F, 31, 35, 34, 50, 40, 00, 89, 55, FC, A3, 34, 50, 40, 00, 75, 07, 8B, C1, A3, 34, 50, 40, 00, F7, D0, A3, 30, 50, 40, 00, 8B, E5, 5D, C3, 5C, 00, 44, 00, 65, 00, 76, 00, 69, 00, 63, 00, 65, 00, 5C, 00, 66, 00, 69, 00, 6C, 00, 64, 00, 43, 00, 6E, 00, 74, 00, 6C, 00, 00, 00, 5C, 00, 44, 00, 6F, 00, 73, 00, 44, 00, 65, 00, 76, 00, 69, 00, 63, 00...
 
[+]

Entropy:
6.5638

Code size:
14 KB (14,336 bytes)

Driver
Display name:
fild

Type:
Kernel device driver (KernelDriver)


Scan fild.Sys - Powered by Reason Core Security