rcvsta.sys

V3 Lite PC recovery

Solusseum Inc

It runs as a Windows 64-bit kernel mode device driver named “XcoveryState”.
Publisher:
Solusseum Inc.  (signed by Solusseum Inc)

Product:
V3 Lite PC recovery

Version:
7.01.35.03 built by: WinDDK

MD5:
ff9e6e6407c972584a894941e5d5c0de

SHA-1:
68df2e35f38c7b3bbad5129c39e9d44328a7ed6c

SHA-256:
aba9082c39b2ccbdb3c1449fefb1571f542606184dee90a3bf9ecadcd1826837

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 1:57:30 AM UTC  (today)

File size:
10.8 KB (11,008 bytes)

Product version:
7.01.35.03

Copyright:
(C) Solusseum Inc. 2006-, All rights reserved.

Original file name:
rcvsta.sys

File type:
Driver (Win64 SYS)

Common path:
C:\Windows\System32\drivers\rcvsta.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/21/2011 9:00:00 AM

Valid to:
5/21/2012 8:59:59 AM

Subject:
CN=Solusseum Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Solusseum Inc, L=Guro-gu, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5D9E43841D3B0D37AFCAC6DCAC34362F

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
192:tDpXaji7yowJL/Kr9ZCApkT1rrZgjlP/rFQ+ql+vKuAr0ITZRA:rXG2YJLjp1P6j/PqnbZRA

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, C8, FC, FF, FF, CC, CC, F8, 09, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 50, 0B, 00, 00, 00, 08, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 30, 0A, 00, 00, 46, 0A, 00, 00, 5E, 0A, 00, 00, 76, 0A, 00, 00, 86, 0A, 00, 00, A6, 0A, 00, 00, BA, 0A, 00, 00, D6, 0A, 00, 00, EE, 0A, 00, 00, 06, 0B, 00, 00, 18, 0B, 00, 00, 30, 0B, 00, 00, 42, 0B, 00, 00, 00, 00, 00, 00, E3, 01, 49, 6F, 66, 43, 6F, 6D, 70, 6C, 65, 74, 65, 52...
 
[+]

Entropy:
6.5670

Driver
Display name:
XcoveryState

Type:
Kernel device driver (KernelDriver)

Group:
Base


Scan rcvsta.sys - Powered by Reason Core Security