mnstlrf.sys

UBT (EU) Ltd.

It runs as a Windows 64-bit file system device driver named “mnstlrf service”.
Publisher:
UBT (EU) Ltd.  (signed and verified)

Version:
2.2.8.23

MD5:
8c35f67846f8bf3109fafd274d11c0dd

SHA-1:
47a71ff211537201a05f36d67bc37bb20db1a534

SHA-256:
398d10a6e916e9efb85f69ff9c655661f50fdfa4e1930f0292696bc7f4c02ccc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/6/2024 7:25:15 PM UTC  (today)

File size:
31.8 KB (32,560 bytes)

Product version:
1.4.0.8710

Original file name:
mnstlrf.sys

File type:
Driver (Win64 SYS)

Language:
Language Neutral

Common path:
C:\Windows\System32\drivers\mnstlrf.sys

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
10/17/2013 1:00:00 AM

Valid to:
10/20/2016 1:00:00 PM

Subject:
CN=UBT (EU) Ltd., O=UBT (EU) Ltd., L=Warwick, S=Warwickshire, C=GB, PostalCode=CV34 6BY, STREET=Exchange Place, STREET=Poseidon Way, SERIALNUMBER=04938684, OID.1.3.6.1.4.1.311.60.2.1.3=GB, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0A85174C41FCDDD1741EB80F47B36C29

File PE Metadata
Compilation timestamp:
5/29/2014 9:40:24 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
768:/fycZchwy8vrIKt50ZCuCIxkir8toJaUyOXK5Y3glUDX9fqTS+vgcI20:HLZchwfsC/Arfquq0

Entry address:
0x92D4

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, 16, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 50, 61, 73, 73, 54, 68, 72, 6F, 75, 67, 68, 21, 44, 72, 69, 76, 65, 72, 45, 6E, 74, 72, 79, 3A, 20, 45, 6E, 74, 65, 72, 65, 64, 0A, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 5C, 00, 44, 00, 65, 00, 76, 00, 69, 00, 63, 00, 65, 00, 5C, 00, 6D, 00, 6E, 00, 73, 00, 74, 00, 6C, 00, 72, 00, 66, 00, 00, 00, 5C, 00, 44, 00...
 
[+]

Entropy:
6.3533

Code size:
17 KB (17,408 bytes)

Driver
Display name:
mnstlrf service

Service name:
mnstlrf

Type:
File system 'filter' driver (FileSystemDriver)

Group:
FSFilter Activity Monitor

Depends on:
FltMgr


Scan mnstlrf.sys - Powered by Reason Core Security