ItlsFF.sys

ITM SYSTEM File Filter Driver

ITM System Co LTD

It runs as a Windows file system device driver named “ITM System Mini-Filter”.
Publisher:
ITM SYSTEM  (signed by ITM System Co LTD)

Product:
ITM SYSTEM File Filter Driver

Description:
ITM Mini-Filter System

Version:
2008

MD5:
c7d3a1602514f075ab451ece31dd4e63

SHA-1:
5953564433904b81038113b2c809ea8b360ff364

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 5:04:49 AM UTC  (today)

File size:
67.4 KB (69,064 bytes)

Product version:
2008

Copyright:
Copyright (C) ITM SYSTEM 2001-2008

Trademarks:
2008 ITM SYSTEM

Original file name:
ItlsFF.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\itlsff.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/11/2009 10:15:31 AM

Valid to:
6/11/2011 10:15:31 AM

Subject:
E=yoosh@itmsystem.com, CN=ITM System Co LTD, O=ITM System Co LTD, C=KR

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
01000000000121CD0B05E2

File PE Metadata
Compilation timestamp:
1/10/2010 9:05:35 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.10

CTPH (ssdeep):
1536:XWGO7jXKYotw2D/mbZJ/2BbpU/DdH7eZoOPfdfK1GrRY0SvAXoNi2:U7jXKYottCth2BbpU5HGPfdfK1GdY0Sv

Entry address:
0xD033

Entry point:
A1, 4C, C8, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 19, A1, 00, C4, 01, 00, 8B, 00, 35, 4C, C8, 01, 00, A3, 4C, C8, 01, 00, 75, 06, 89, 0D, 4C, C8, 01, 00, E9, 3D, FC, FF, FF, CC, B8, D1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, E2, D8, 00, 00, 5C, C3, 00, 00, A0, D1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 2C, D9, 00, 00, 44, C3, 00, 00, F4, D0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 48, DD, 00, 00, 98, C2, 00, 00, DC, D0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, D8, DD, 00, 00, 80, C2, 00...
 
[+]

Entropy:
6.5865

Code size:
52 KB (53,248 bytes)

Driver
Display name:
ITM System Mini-Filter

Service name:
ItlsFF

Type:
File system 'filter' driver (FileSystemDriver)

Group:
Filter


Scan ItlsFF.sys - Powered by Reason Core Security