miniicpt.sys

G DATA AntiVirusKit

G DATA Software AG

It runs as a Windows kernel mode device driver named “GDMnIcpt”.
Publisher:
G DATA Software AG  (signed and verified)

Product:
G DATA AntiVirusKit

Description:
Filesystem MiniInterceptor (Mini Filter)

Version:
1, 0, 2, 7

MD5:
e07bb6d958dc2a000065c9e696050fae

SHA-1:
77c2088c01efcd9bc4484dfadb74a8f36c3c6de8

SHA-256:
f1128c124ed71a468c3869b09c6620ae76e925ad583eed1831dfdfb0ef6a74a4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/20/2024 12:20:11 AM UTC  (today)

File size:
46.2 KB (47,312 bytes)

Product version:
15, 0, 0, 0

Copyright:
G DATA Software AG 2006

File type:
Driver (Win32 SYS)

Language:
German (Germany)

Common path:
C:\Windows\System32\drivers\miniicpt.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/6/2006 4:48:30 PM

Valid to:
12/6/2007 4:48:30 PM

Subject:
E=sign@gdata.de, CN=G DATA Software AG, O=G DATA Software AG, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000010F5873A0CE

File PE Metadata
Compilation timestamp:
3/27/2007 1:24:56 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
768:qeUaTAc80mzPYAh9jCZyGNYSdMcwZodsQ/yUpqZjxL3iJiR:HUiwjh9+VYSOcwZWsQ/i9WiR

Entry address:
0x8077

Entry point:
8B, FF, 55, 8B, EC, A1, B8, 66, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1E, 8B, 15, C0, 5C, 01, 00, B8, B8, 66, 01, 00, C1, E8, 08, 33, 02, A3, B8, 66, 01, 00, 75, 07, 8B, C1, A3, B8, 66, 01, 00, F7, D0, A3, BC, 66, 01, 00, 5D, E9, D5, F9, FF, FF, CC, 43, 00, 6C, 00, 61, 00, 73, 00, 73, 00, 00, 00, 45, 72, 72, 6F, 72, 20, 63, 6F, 6E, 73, 74, 72, 75, 63, 74, 69, 6E, 67, 20, 48, 65, 61, 70, 20, 50, 6F, 6F, 6C, 00, CC, 4D, 69, 6E, 69, 49, 63, 70, 74, 20, 66, 61, 69, 6C, 65, 64, 20, 74, 6F, 20...
 
[+]

Code size:
29.8 KB (30,464 bytes)

Driver
Display name:
GDMnIcpt

Type:
Kernel device driver (KernelDriver)


Scan miniicpt.sys - Powered by Reason Core Security