npf.sys

WinPcap

Riverbed Technology, Inc.

npf.sys is the library is part of WinPcap a Windows link-layer network access packet capture and filtering engine and is recompiled by Riverbed Technology, Inc..
Publisher:
Riverbed Technology, Inc.  (signed and verified)

Product:
WinPcap

Description:
npf.sys (NT4) Kernel Driver

Version:
4.1.0.2980

MD5:
27f7516558ca25c2bd4ce879b4e7ae05

SHA-1:
25caf334f2efcd208b791ac6353e17d95bc691bc

SHA-256:
ac6468c4a8d2dd8176d851f9059d5ca87b796b1976021c17d7dbc9afd3d379ab

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 5:07:20 AM UTC  (today)

File size:
47.7 KB (48,888 bytes)

Product version:
4.1.0.2980

Copyright:
Copyright © 2010-2013 Riverbed Technology, Inc. Copyright © 2005-2010 CACE Technologies. Copyright © 1999-2005 NetGroup, Politecnico di Torino.

Original file name:
npf.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Program Files\hearthstone\hearth log\hearthstats\$sysdir\drivers\npf.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/26/2012 2:00:00 AM

Valid to:
10/28/2015 12:59:59 AM

Subject:
CN="Riverbed Technology, Inc.", OU=Product Marketing, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Riverbed Technology, Inc.", L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1402AEEF0D31BE743E73F6A7A960C4F4

File PE Metadata
Compilation timestamp:
3/1/2013 2:40:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
6.0

CTPH (ssdeep):
768:6X3pgAJd8qsPLBf904J0ZVkEpGTrELHv1yTk88SwVESJGKRV1:ozjAPL9P0GTQLHv1yTkXSMJDj1

Entry address:
0x60A

Entry point:
55, 8B, EC, 83, EC, 4C, 83, 65, FC, 00, 53, 56, 57, FF, 75, 0C, 66, C7, 45, F4, 18, 00, 66, C7, 45, F6, 1A, 00, BE, F0, 05, 01, 00, E8, 42, 01, 00, 00, 8B, 1D, 70, 03, 01, 00, 68, 20, 55, 01, 00, 68, 00, 5B, 01, 00, FF, D3, FF, 15, B4, 02, 01, 00, 0F, BE, C0, 6A, 0E, A3, F8, 5A, 01, 00, 59, 33, C0, 8D, 7D, B4, 6A, 38, F3, AB, 20, 45, B5, 21, 45, B8, 8B, 45, F4, C6, 45, B4, 03, 89, 45, E4, 8D, 45, B4, 50, 8D, 45, FC, 68, D4, 59, 01, 00, 50, C7, 45, BC, 10, 21, 01, 00, C7, 45, C0, 5E, 22, 01, 00, C7, 45, C4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
22.3 KB (22,848 bytes)

Scan npf.sys - Powered by Reason Core Security