ShDrv.sys

TSX_R2

Wontok, Inc.

It runs as a Windows 64-bit kernel mode device driver named “SHDrv”.
Publisher:
Wontok, Inc.  (signed and verified)

Product:
TSX_R2

Description:
Service Hardening Driver

Version:
2.0.2381.1015

MD5:
98a6fb500f2c04ed13cbcd06d79da3ab

SHA-1:
433ae61288ed92af9d8b190a275c214da71c5f1f

SHA-256:
6a0cc960cccf4f461fabe9e044a9ec57a8f0ea481492130c0dabcb180c21e4dc

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/18/2024 2:37:11 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Crypt.XPACK.Gen
7.11.30.172

File size:
260.7 KB (266,952 bytes)

Product version:
2.0.2381

Copyright:
(C) 2002-2014 Wontok, Inc. All rights reserved

Original file name:
ShDrv.sys

File type:
Driver (Win64 SYS)

Language:
English

Common path:
C:\Windows\System32\drivers\shdrv.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/7/2013 11:00:00 AM

Valid to:
12/8/2014 10:59:59 AM

Subject:
CN="Wontok, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Wontok, Inc.", L=Palm Beach Gardens, S=Florida, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
30071A4B224C3059C709F4E22C305C41

File PE Metadata
Compilation timestamp:
9/25/2014 5:18:08 PM

OS version:
6.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
11.0

CTPH (ssdeep):
3072:y6QdpPQv2uWurbkEjK1vw7sA9u272M7rSpVqSci+AJP6XMblcOt8:y5nPAgL1vGsA9eM7roq3iBrcE8

Entry address:
0x44070

Entry point:
48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8B, DA, 48, 8B, F9, E8, 83, FF, FF, FF, 48, 8B, D3, 48, 8B, CF, 48, 8B, 5C, 24, 30, 48, 83, C4, 20, 5F, E9, F6, 14, FC, FF, CC, CC, C8, 40, 04, 00, 00, 00, 00, 00, 00, 00, 00, 00, C2, 53, 04, 00, 00, C0, 02, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 30, 46, 04, 00, 00, 00, 00, 00, 4A, 46, 04, 00, 00, 00, 00, 00, 5A, 46, 04, 00, 00, 00, 00, 00, 76, 46, 04, 00, 00, 00, 00, 00, 8A, 46, 04, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.9125

Code size:
175 KB (179,200 bytes)

Driver
Display name:
SHDrv

Type:
Kernel device driver (KernelDriver)

Depends on:
Apix


Scan ShDrv.sys - Powered by Reason Core Security