r1vssfltr.sys

Writable VSS Driver

Idera

It runs as a Windows kernel mode device driver named “Writable VSS Filter Driver”.
Publisher:
R1Soft  (signed by Idera)

Product:
Writable VSS Driver

Version:
3, 0, 0, 8

MD5:
d0bb9a8bacbe4db624162d3a1f9257ba

SHA-1:
ca13ae3cfc08e55eb25fe1e2620752b2636d69ad

SHA-256:
9ec379f272e37bf20e5838b0608c2442a848a16008ee0eedd2c1ed5d8e206d79

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 10:58:46 PM UTC  (today)

File size:
27.7 KB (28,392 bytes)

Product version:
3, 0, 0, 8

Copyright:
Copyright (C) 2011

Original file name:
r1vssfltr.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\r1vssfltr.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Subject:
CN=Idera, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Idera, L=Houston, S=Texas, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4BE841F6159867AFCF6C61B4C476753A

File PE Metadata
Compilation timestamp:
12/17/2011 7:28:30 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
384:X6QsXr8L7XBVEgOG1BwXptT2LeSXHgU6aXVTF72dJnYPLQa6jW6ReM7Y9:q1IL71s5tTcAU6aFT4ymRts

Entry address:
0x603E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 8E, D6, FF, FF, CC, CC, 98, 60, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 4C, 67, 00, 00, 0C, 40, 00, 00, 8C, 60, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 82, 67, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 5A, 67, 00, 00, 6E, 67, 00, 00, 00, 00, 00, 00, F2, 61, 00, 00, FC, 61, 00, 00, 14, 62, 00, 00, 22, 62, 00, 00, 36, 62, 00, 00, 46, 62, 00, 00, 50, 62, 00, 00, 5E, 62, 00, 00, 6C, 62, 00, 00, 76, 62...
 
[+]

Entropy:
6.5503

Code size:
14 KB (14,336 bytes)

Driver
Display name:
Writable VSS Filter Driver

Service name:
r1vssfltr

Type:
Kernel device driver (KernelDriver)

Group:
PnP Filter


Scan r1vssfltr.sys - Powered by Reason Core Security