vcache.sys

GTK

RSJ Software GmbH

It runs as a Windows file system device driver named “vcache”.
Publisher:
RSJ Software GmbH  (signed and verified)

Product:
GTK

Version:
0.12.0003

MD5:
f93964f645f9f7b128be3c942f52b7c0

SHA-1:
9701276a79d5e09ec2d97d211bb2f1a23cd4183e

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/26/2024 1:27:25 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.CDB
1.3.0.4924

File size:
45.9 KB (46,992 bytes)

Product version:
0.12.0003

Copyright:
Copyright (C) 2007-2009 by RSJ Software GmbH Germering. All rights reserved.

Original file name:
GTK

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\vcache.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/16/2009 12:26:23 PM

Valid to:
1/16/2012 12:26:23 PM

Subject:
E=info@rsj.de, CN=RSJ Software GmbH, O=RSJ Software GmbH, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000011EDF68BB3F

File PE Metadata
Compilation timestamp:
2/26/2009 5:08:10 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
768:uGe0fLRtc4xFokcL55/P+awx18DMqWNU+K74FV2BRpWbSDHCHFAH42vSimE:mmncqFgT/P+ay18DMqqU+NV2/S2Y1ib

Entry address:
0x8A05

Entry point:
8B, FF, 55, 8B, EC, A1, C0, 7F, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1A, A1, 2C, 4C, 01, 00, 8B, 00, 35, C0, 7F, 01, 00, A3, C0, 7F, 01, 00, 75, 07, 8B, C1, A3, C0, 7F, 01, 00, F7, D0, A3, C4, 7F, 01, 00, 5D, E9, 13, 93, FF, FF, CC, 6C, 8A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, A0, 8E, 00, 00, 80, 4B, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 24, 8B, 00, 00, 32, 8B, 00, 00, 3C, 8B, 00, 00, 56, 8B, 00, 00, 6E, 8B, 00, 00, 82, 8B, 00, 00, 98...
 
[+]

Code size:
19 KB (19,456 bytes)

Driver
Display name:
vcache

Description:
VCache Driver

Type:
File system 'filter' driver (FileSystemDriver)

Depends on:
vfilter


Scan vcache.sys - Powered by Reason Core Security