rcvsta.sys

V3 Lite PC recovery

Solusseum Inc

It runs as a Windows 64-bit kernel mode device driver named “XcoveryState”.
Publisher:
Solusseum Inc.  (signed by Solusseum Inc)

Product:
V3 Lite PC recovery

Version:
7.01.35.03 built by: WinDDK

MD5:
d665efe3918a93c6813f5759a3909961

SHA-1:
eb22aa1bde4e5b78597ef0e9d2deb679ba9bcadc

SHA-256:
0438a6871eb62f592954ba2a1bb07f08398fd0d65bc5660030f6ae7f061f1562

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 3:03:05 PM UTC  (today)

File size:
12.8 KB (13,056 bytes)

Product version:
7.01.35.03

Copyright:
(C) Solusseum Inc. 2006-, All rights reserved.

Original file name:
rcvsta.sys

File type:
Driver (Win64 SYS)

Common path:
C:\Windows\System32\drivers\rcvsta.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/21/2011 9:00:00 AM

Valid to:
5/21/2012 8:59:59 AM

Subject:
CN=Solusseum Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Solusseum Inc, L=Guro-gu, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5D9E43841D3B0D37AFCAC6DCAC34362F

File PE Metadata
Compilation timestamp:
3/21/2012 9:54:02 PM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
192:CSB7Rb8TqXajifyowJL/Kr9ZCApkT1rrZgjlP/rFQ+ql+vKuAro6:lN8TqXGiYJLjp1P6j/PqnL

Entry address:
0x5064

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, 86, BF, FF, FF, CC, CC, B0, 50, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 42, 52, 00, 00, 00, 20, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 20, 51, 00, 00, 00, 00, 00, 00, 40, 51, 00, 00, 00, 00, 00, 00, 58, 51, 00, 00, 00, 00, 00, 00, 70, 51, 00, 00, 00, 00, 00, 00, 82, 51, 00, 00, 00, 00, 00, 00, 96, 51, 00, 00, 00, 00, 00, 00, B2, 51, 00, 00...
 
[+]

Entropy:
6.0453

Code size:
2.5 KB (2,560 bytes)

Driver
Display name:
XcoveryState

Type:
Kernel device driver (KernelDriver)

Group:
Base


Scan rcvsta.sys - Powered by Reason Core Security