filectl.sys

Wuhan os-easy technology co., ltd

It runs as a Windows file system device driver named “FileCtl”.
Publisher:
Wuhan os-easy technology co., ltd  (signed and verified)

MD5:
98decb343c74c1c08135f4f926f625cf

SHA-1:
186aa43385e3ce8b110bf9a7ef8d2497407f672b

SHA-256:
177ebb72490317c98c4fa7d99b11f81b6688f8cb2212e1d6a44c8e3b35057d97

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/4/2024 6:18:01 PM UTC  (today)

File size:
33.1 KB (33,920 bytes)

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\filectl.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/20/2010 8:00:00 AM

Valid to:
12/20/2011 7:59:59 AM

Subject:
CN="Wuhan os-easy technology co., ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Wuhan os-easy technology co., ltd", L=Wuhan, S=Hubei, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1AC973C465F546C5855FC2085FF20F8D

File PE Metadata
Compilation timestamp:
7/9/2011 11:39:36 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
768:0EAtQXxRBf/BvqK6sVdKkfGgap4FKVsME2m:Jlxn/tqK6sVdNDxfN

Entry address:
0x5749

Entry point:
8B, FF, 55, 8B, EC, A1, 04, 52, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1A, A1, 10, 4F, 01, 00, 8B, 00, 35, 04, 52, 01, 00, A3, 04, 52, 01, 00, 75, 07, 8B, C1, A3, 04, 52, 01, 00, F7, D0, A3, 08, 52, 01, 00, 5D, E9, 7F, FD, FF, FF, CC, 45, 78, 69, 74, 20, 46, 69, 6C, 65, 43, 74, 6C, 21, 20, 0A, 00, 46, 69, 6C, 65, 43, 74, 6C, 3A, 20, 53, 74, 61, 72, 74, 20, 66, 69, 6C, 74, 65, 72, 69, 6E, 67, 20, 66, 61, 69, 6C, 65, 64, 21, 0A, 00, 46, 69, 6C, 65, 43, 74, 6C, 3A, 20, 43, 72, 65, 61, 74, 65...
 
[+]

Entropy:
6.7937

Code size:
21.9 KB (22,400 bytes)

Driver
Display name:
FileCtl

Type:
File system 'filter' driver (FileSystemDriver)

Group:
FSFilter Bottom


Scan filectl.sys - Powered by Reason Core Security