snswfp.sys

SafenSoft SysWatch

SnS Soft

It runs as a Windows 64-bit kernel mode device driver named “SnsWfp”.
Publisher:
S.N.Safe&Software  (signed by SnS Soft)

Product:
SafenSoft SysWatch

Description:
SafenSoft SysWatch Network Driver

Version:
3.6.1.21

MD5:
235114e2fb8635c38d2ced0a3b9fdd5d

SHA-1:
026a2a0933f7792a7e64bf3db0b0d5146d781cb9

SHA-256:
555ceb852c42a091b9ca016c172ba0bad63cb4f79e1c3d93fb1d76b1b057299e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/8/2024 2:49:43 PM UTC  (today)

File size:
26.3 KB (26,912 bytes)

Product version:
3.6.1.0

Copyright:
© S.N.Safe&Software, 2004-2011. All rights reserved.

Original file name:
snswfp.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\snswfp.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/30/2011 2:00:00 AM

Valid to:
6/5/2012 1:59:59 AM

Subject:
CN=SnS Soft, OU=R&D, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=SnS Soft, L=Moscow, S=Moscow, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2A3BF7AEAA203975A48592156B874F87

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
384:LZe4jLRxiPPxW4XdHg0rl7LQLn1dCn6mnKYJLca6j2FeMhJZX2:A8HyPxWIdAGlAr1o6mnDLFmom

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, 72, A8, FF, FF, CC, CC, F8, 71, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 60, 75, 00, 00, 10, 41, 00, 00, 20, 71, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 46, 78, 00, 00, 38, 40, 00, 00, E8, 70, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 94, 78, 00, 00, 00, 40, 00, 00, 00, 71, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, E4, 78, 00, 00, 18, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.3074

Driver
Display name:
SnsWfp

Description:
WFP-filter Event Service

Type:
Kernel device driver (KernelDriver)

Group:
FSFilter Anti-Virus


Scan snswfp.sys - Powered by Reason Core Security