trufosalt.sys

BitDefender Antivirus

BitDefender Test Certificate

It runs as a Windows file system device driver named “TrufosAlt”.
Publisher:
BitDefender S.R.L.  (signed by BitDefender Test Certificate)

Product:
BitDefender Antivirus

Description:
Trufos Kernel Module

Version:
2.3.410.9733 Free Build built by: WinDDK

MD5:
6837d72d25e88c4446c53bd9d7a322d7

SHA-1:
743d6f3d3da7e95e9d234438fa61384a2368f7a4

SHA-256:
0b8249be0ec78c2ef058a1d3d6516d9511e875b15903eba42d5a4adc6cbe279f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 7:31:49 AM UTC  (today)

File size:
299.1 KB (306,320 bytes)

Product version:
14.0.0.0

Copyright:
(c) 2010 BitDefender S.R.L.

Original file name:
TRUFOS.SYS

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\trufosalt.sys

Digital Signature
Authority:
BitDefender Test Certificate

Valid from:
7/3/2006 10:22:31 AM

Valid to:
1/1/2040 1:59:59 AM

Subject:
CN=BitDefender Test Certificate

Issuer:
CN=BitDefender Test Certificate

Serial number:
7FC26313C76955974374AE1D04108BD5

File PE Metadata
Compilation timestamp:
8/11/2011 2:17:39 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
6144:zKpvWDBfQPqUKwFlFlFlF7QC/5fC1cvVEq2tK:zwvWDBfQ5FlFlFlFUY5fC1c20

Entry address:
0x4E03E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, C2, 2F, FB, FF, CC, CC, 34, E1, 04, 00, 00, 00, 00, 00, 00, 00, 00, 00, 0A, EB, 04, 00, 94, 20, 04, 00, 1C, E1, 04, 00, 00, 00, 00, 00, 00, 00, 00, 00, 48, EB, 04, 00, 7C, 20, 04, 00, A0, E0, 04, 00, 00, 00, 00, 00, 00, 00, 00, 00, 3A, ED, 04, 00, 00, 20, 04, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 24, F1, 04, 00, EA, F0, 04, 00, D8, F0, 04, 00, C2, F0, 04, 00, A6, F0, 04, 00, 8A, F0, 04, 00, 76, F0, 04, 00, 2A, ED...
 
[+]

Entropy:
6.4183

Code size:
265 KB (271,360 bytes)

Driver
Display name:
TrufosAlt

Description:
TrufosAlt Mini-Filter Driver

Type:
File system 'filter' driver (FileSystemDriver)

Group:
FSFilter Activity Monitor

Depends on:
FltMgr


Scan trufosalt.sys - Powered by Reason Core Security