r1fltr.sys

Volume Modification Tracker

Idera

It runs as a Windows kernel mode device driver named “Volume Modification Filter Driver”.
Publisher:
R1Soft  (signed by Idera)

Product:
Volume Modification Tracker

Version:
1, 0, 0, 5

MD5:
af78641b554481a5596121907ad0d8c7

SHA-1:
960475949c0d2929ee5898a8fe9f525fdb384767

SHA-256:
b47a1ca3a0bb6b2b89f1d69ef561c288d094290acc92362a62ad1caae352c838

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 11:18:35 AM UTC  (today)

File size:
20.1 KB (20,584 bytes)

Product version:
1, 0, 0, 5

Copyright:
Copyright (C) 2011

Original file name:
r1fltr.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\r1fltr.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Subject:
CN=Idera, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Idera, L=Houston, S=Texas, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4BE841F6159867AFCF6C61B4C476753A

File PE Metadata
Compilation timestamp:
2/23/2011 12:34:27 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
384:jCS1LIGjPDCUoG/jrZEK4HiZnYPLQa6jW6ReMGGC:/nZpJEnHmymRcGC

Entry address:
0x21BE

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 4E, F8, FF, FF, CC, CC, 18, 22, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, EA, 26, 00, 00, 8C, 1D, 00, 00, 0C, 22, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 20, 27, 00, 00, 80, 1D, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, F8, 26, 00, 00, 0C, 27, 00, 00, 00, 00, 00, 00, 28, 23, 00, 00, 3C, 23, 00, 00, 46, 23, 00, 00, 56, 23, 00, 00, 6E, 23, 00, 00, 7C, 23, 00, 00, 92, 23, 00, 00, AA, 23, 00, 00, BE, 23, 00, 00, DA, 23...
 
[+]

Entropy:
6.7226

Code size:
7.8 KB (7,936 bytes)

Driver
Display name:
Volume Modification Filter Driver

Service name:
r1fltr

Type:
Kernel device driver (KernelDriver)

Group:
PnP Filter


Scan r1fltr.sys - Powered by Reason Core Security