KProcessCheck2.sys

TrustDefender Kernel Forensics Engine

Symbiotic Technologies Pty Ltd

This is installed with TrustDefender.
Publisher:
Symbiotic Technologies Pty Ltd  (signed and verified)

Product:
TrustDefender Kernel Forensics Engine

Description:
KProcessCheck2 - Kernel Forensics Engine

Version:
3.4.3.1095

MD5:
3057957f079c08d2078840a63ceed52d

SHA-1:
5f529d72b6116e29f867761688a1d4bc7bd347f0

SHA-256:
39701c42a54a09a954aac24dc97d98972425736702112c675e21b5c819df4918

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 2:57:43 AM UTC  (today)

File size:
60.2 KB (61,632 bytes)

Product version:
3.4.3.1095

Copyright:
(C) 2005-2011 Symbiotic Technologies Pty Ltd. All rights reserved

Original file name:
KProcessCheck2.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Program Files\trustdefender\trustdefender\kprocesscheck2.sys

Digital Signature
Authority:
DigiCert Inc

Valid from:
11/11/2013 11:00:00 AM

Valid to:
11/19/2014 11:00:00 PM

Subject:
CN=Symbiotic Technologies Pty Ltd, O=Symbiotic Technologies Pty Ltd, L=San Jose, S=California, C=US

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0CD1D433C6C0A7F2E62133537AF98C1A

File PE Metadata
Compilation timestamp:
3/27/2014 2:57:53 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
10.0

CTPH (ssdeep):
1536:XGotpbFITsiUjAIt3bosUT9NmCCleb08AoKgNwRMLKr:FrFI4iAAIt3bosqfCleJKgNwRh

Entry address:
0x7E90

Entry point:
48, 89, 5C, 24, 08, 57, 48, 83, EC, 50, 48, 8B, F9, 48, 89, 0D, 04, 41, 00, 00, 48, 8D, 15, 45, 1B, 00, 00, 48, 8D, 0D, 6E, 41, 00, 00, FF, 15, F0, 11, 00, 00, 48, 8D, 15, 61, 1B, 00, 00, 48, 8D, 0D, 9A, 41, 00, 00, FF, 15, DC, 11, 00, 00, 4C, 8B, 5F, 28, 33, DB, 4C, 89, 1D, B7, 41, 00, 00, 48, 89, 1D, B8, 41, 00, 00, E8, 3B, FE, FF, FF, 85, C0, 74, 10, B8, 01, 00, 00, C0, 48, 8B, 5C, 24, 60, 48, 83, C4, 50, 5F, C3, 48, 8D, 05, B0, 40, 00, 00, 4C, 8D, 05, 19, 41, 00, 00, 41, B9, 22, 00, 00, 00, 48, 89, 44...
 
[+]

Entropy:
6.3725

Code size:
39 KB (39,936 bytes)

The file KProcessCheck2.sys has been discovered within the following programs.

TrustDefender  by Symbiotic Technologies Pty Ltd
Publisher's description - “TrustDefender is designed to protect your computer from attack by Online Criminals, identify and stop unknown software or crimeware, ensuring that your computer is Safe&Secure during an online business session or banking transaction.”
www.trustdefender.com
6% remove it
 
Powered by Should I Remove It?

Scan KProcessCheck2.sys - Powered by Reason Core Security