nsavflt.sys

Filter Driver

NHN corp.

It runs as a Windows kernel mode device driver named “NSavFlt”.
Publisher:
NHN  (signed by NHN corp.)

Product:
Filter Driver

Version:
2010,12,17,1

MD5:
2fb16b48b4976bb7d60d158ce2b1c7a8

SHA-1:
2de02b822281728c0fb1332ec3c091cc561c1d34

SHA-256:
026f699f28866c859279f84d13bef66fc2d83f82a74ae5ae1071915dcc24d42e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 6:48:19 AM UTC  (today)

File size:
63.4 KB (64,936 bytes)

Product version:
2010,12,17,1

Copyright:
Copyright (C) NHN 2010

Original file name:
nsavflt.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\nsavflt.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/1/2010 9:00:00 AM

Valid to:
12/2/2011 8:59:59 AM

Subject:
CN=NHN corp., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=NHN corp., L=Seongnam-si, S=Gyeonggi-do, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
63ED650D39536379EBB5E8ACA1996961

File PE Metadata
Compilation timestamp:
12/17/2010 3:51:10 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.0

CTPH (ssdeep):
768:1gbSF1wJ3dsL+a+uybqdIgJSGCMLHM1HS:uGIJyCNw5JSGCML

Entry address:
0x4B0C

Entry point:
55, 8B, EC, 83, EC, 58, A1, E4, 4E, 01, 00, 83, 0D, 14, BE, 01, 00, FF, 53, 56, 57, 6A, 08, 59, BE, C4, 4A, 01, 00, 8D, 7D, D0, F3, A5, 6A, 0A, 59, BE, E4, 4A, 01, 00, 8D, 7D, A8, F3, A5, 33, F6, C7, 05, 10, BE, 01, 00, 80, 69, 67, FF, 39, 30, 0F, 87, 15, 02, 00, 00, E8, 7E, BB, FF, FF, E8, 9F, BB, FF, FF, A1, 1C, 52, 01, 00, 83, F8, 05, 74, 09, 83, F8, 06, 0F, 85, F8, 01, 00, 00, 8B, 5D, 08, A1, E0, 4E, 01, 00, 89, 1D, 00, 52, 01, 00, 66, 81, 38, 65, 05, 7D, 0A, C7, 05, 80, 51, 01, 00, 38, 00, 00, 00, E8...
 
[+]

Entropy:
3.8815

Developed / compiled with:
Microsoft Visual C++

Code size:
20.4 KB (20,864 bytes)

Driver
Display name:
NSavFlt

Type:
Kernel device driver (KernelDriver)


Scan nsavflt.sys - Powered by Reason Core Security