sdactmon.sys

SDActMon

Max Secure Software India Pvt. Ltd.

The file sdactmon.sys, “Max Secure Software Active Monitor Driver” by Max Secure Software India Pvt has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a Windows 64-bit file system device driver named “SDActMon”.
Publisher:
Max Secure Software  (signed by Max Secure Software India Pvt. Ltd.)

Product:
SDActMon

Description:
Max Secure Software Active Monitor Driver

Version:
2, 0, 1, 1

MD5:
c085cd89c20a55c95cefe3beba2042ee

SHA-1:
5fbf51478bfb8b52e704459de446a8eed658d671

SHA-256:
1e6ecd05836d8d2b512df258666a45da34664751109699ef1064e748b6266390

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 11:16:19 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.MaxSecure.Optional (L)
17.3.5.4

File size:
117.5 KB (120,352 bytes)

Product version:
19, 0, 2, 1

Copyright:
(c) Max Secure Software 2011. All rights reserved.

Original file name:
SDActMon

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\sdactmon.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/3/2012 2:00:08 AM

Valid to:
7/24/2014 10:57:41 AM

Subject:
E=tech@maxpcsecure.com, CN=Max Secure Software India Pvt. Ltd., O=Max Secure Software India Pvt. Ltd., L=pune, S=MH, C=IN

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11216A69882C6D7835A9F4F1D6DCB7AC9C32

File PE Metadata
Compilation timestamp:
8/31/2012 10:11:49 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

Entry address:
0x1D360

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, 8A, FC, FF, FF, CC, CC, 68, D4, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, FA, D9, 01, 00, A8, 50, 00, 00, C0, D3, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 06, DC, 01, 00, 00, 50, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, D4, DB, 01, 00, 00, 00, 00, 00, B4, DB, 01, 00, 00, 00, 00, 00, A0, DB, 01, 00, 00, 00, 00, 00, 7C, DB, 01, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.0565

Code size:
36 KB (36,864 bytes)

Driver
Display name:
SDActMon

Type:
File system 'filter' driver (FileSystemDriver)

Group:
FSFilter Anti-Virus

Depends on:
FltMgr


Remove sdactmon.sys - Powered by Reason Core Security