trufosalt.sys

BitDefender Antivirus

BitDefender Test Certificate

It runs as a Windows file system device driver named “TrufosAlt”.
Publisher:
BitDefender S.R.L.  (signed by BitDefender Test Certificate)

Product:
BitDefender Antivirus

Description:
Trufos Kernel Module

Version:
2.3.401.9649 Free Build built by: WinDDK

MD5:
afd6f6d6e34444b5fe9a82445f30436b

SHA-1:
d0fe9f6ed4da06af96017811a5a1db1dbc2155df

SHA-256:
6407455f4cd15f9f2b1a96ab8dfe29fe3cd87f7f12967b4ac71cb3c68b93a039

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 1:05:40 PM UTC  (today)

File size:
299.1 KB (306,320 bytes)

Product version:
14.0.0.0

Copyright:
(c) 2010 BitDefender S.R.L.

Original file name:
TRUFOS.SYS

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\trufosalt.sys

Digital Signature
Authority:
BitDefender Test Certificate

Valid from:
7/3/2006 2:22:31 AM

Valid to:
12/31/2039 5:59:59 PM

Subject:
CN=BitDefender Test Certificate

Issuer:
CN=BitDefender Test Certificate

Serial number:
7FC26313C76955974374AE1D04108BD5

File PE Metadata
Compilation timestamp:
7/20/2011 6:34:47 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
6144:/UKqC/T0vAPbUapsV1V1V1V3jSIyKCHMUZmEd2r:/UzC/T0vA+V1V1V1V7yKCHMn

Entry address:
0x4E03E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, C2, 2F, FB, FF, CC, CC, 34, E1, 04, 00, 00, 00, 00, 00, 00, 00, 00, 00, 0A, EB, 04, 00, 94, 20, 04, 00, 1C, E1, 04, 00, 00, 00, 00, 00, 00, 00, 00, 00, 48, EB, 04, 00, 7C, 20, 04, 00, A0, E0, 04, 00, 00, 00, 00, 00, 00, 00, 00, 00, 3A, ED, 04, 00, 00, 20, 04, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 24, F1, 04, 00, EA, F0, 04, 00, D8, F0, 04, 00, C2, F0, 04, 00, A6, F0, 04, 00, 8A, F0, 04, 00, 76, F0, 04, 00, 2A, ED...
 
[+]

Entropy:
6.4182

Code size:
265 KB (271,360 bytes)

Driver
Display name:
TrufosAlt

Description:
TrufosAlt Mini-Filter Driver

Type:
File system 'filter' driver (FileSystemDriver)

Group:
FSFilter Activity Monitor

Depends on:
FltMgr


Scan trufosalt.sys - Powered by Reason Core Security