FStopW.Sys

F-StopW Version 3.16D

Frisk Software International Ltd

It runs as a Windows file system device driver named “FPA_RTP”.
Publisher:
Frisk Software International - www.f-prot.com  (signed by Frisk Software International Ltd)

Product:
F-StopW Version 3.16D

Version:
3.16D

MD5:
cb52ab86bdcc6e35a452bf2ca69405c1

SHA-1:
3c797726d9c78a64474aee2217096add23d3a272

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/1/2024 10:44:52 AM UTC  (today)

File size:
409.8 KB (419,656 bytes)

Product version:
3.16D

Copyright:
Copyright © 2005 Frisk Software International

Original file name:
FStopW.Sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\fstopw.sys

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
2/22/2005 12:06:52 PM

Valid to:
3/5/2006 5:33:41 PM

Subject:
CN=Frisk Software International Ltd, OU=Provided by Dulkóðun Islandia - umboðsaðili thawte, OU=Development and Distribution Department, O=Frisk Software International Ltd, L=Reykjavik, S=Reykjavik, C=IS

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
20EA27

File PE Metadata
Compilation timestamp:
11/15/2005 2:42:54 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.10

CTPH (ssdeep):
6144:edHl56XQ3yMRXTiwXIhgXRK65KysTE08lWEV7i0WRZjeTT/Odii2gy1VA9nepqTz:2lPyUi8IhgXNjbhlWa2RZ5i108q3

Entry address:
0x629AF

Entry point:
A1, 80, 67, 06, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 19, A1, A8, 50, 06, 00, 8B, 00, 35, 80, 67, 06, 00, A3, 80, 67, 06, 00, 75, 06, 89, 0D, 80, 67, 06, 00, E9, ED, FE, FF, FF, CC, 2C, 2A, 06, 00, 00, 00, 00, 00, 00, 00, 00, 00, EA, 2E, 06, 00, 10, 50, 05, 00, 1C, 2A, 06, 00, 00, 00, 00, 00, 00, 00, 00, 00, 38, 2F, 06, 00, 00, 50, 05, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 0E, 2F, 06, 00, F8, 2E, 06, 00, 24, 2F, 06, 00, 00, 00, 00, 00, 74, 2B, 06...
 
[+]

Code size:
340.8 KB (348,928 bytes)

Driver
Display name:
FPA_RTP

Type:
File system 'filter' driver (FileSystemDriver)

Group:
Filter


Scan FStopW.Sys - Powered by Reason Core Security