VTrack.sys

Symantec System Recovery

Symantec Corporation

It runs as a Windows 64-bit kernel mode device driver named “Symantec Volume Change Tracking Driver”.
Publisher:
Symantec  (signed by Symantec Corporation)

Product:
Symantec™ System Recovery

Description:
Symantec Filter Driver for tracking changed block(s).

Version:
11.0.1.47550

MD5:
ba50771f73ea5c1d54cc470372cd87b1

SHA-1:
d96c2c897731459155c438e0c3bb0cf0098ac817

SHA-256:
3264e103dafd740ee117c56171a8554564d81797ee334c954529cffa906e8dcc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 10:11:22 PM UTC  (today)

File size:
343 KB (351,224 bytes)

Product version:
11.0

Copyright:
Copyright © 2013 Symantec Corporation. All rights reserved. Use of this product is subject to license terms.

Trademarks:
Symantec®, the Symantec logo and Symantec™ System Recovery are trademarks or registered trademarks of Symantec Corporation.

Original file name:
VTrack.sys

File type:
Driver (Win64 SYS)

Language:
Language Neutral

Common path:
C:\Windows\System32\drivers\vtrack.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/8/2011 5:00:00 PM

Valid to:
9/8/2013 4:59:59 PM

Subject:
CN=Symantec Corporation, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=IMG, O=Symantec Corporation, L=Heathrow, S=Florida, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7B00EB4233C0876E11580566D44735FE

File PE Metadata
Compilation timestamp:
4/8/2013 7:31:44 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

Entry address:
0x56064

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, AE, F9, FA, FF, CC, CC, B0, 60, 05, 00, 00, 00, 00, 00, 00, 00, 00, 00, 52, 6B, 05, 00, 00, E0, 04, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 64, 05, 00, 00, 00, 00, 00, 0C, 64, 05, 00, 00, 00, 00, 00, 1C, 64, 05, 00, 00, 00, 00, 00, 34, 64, 05, 00, 00, 00, 00, 00, 4C, 64, 05, 00, 00, 00, 00, 00, 62, 64, 05, 00, 00, 00, 00, 00, 84, 64, 05, 00...
 
[+]

Entropy:
6.1599

Code size:
317 KB (324,608 bytes)

Driver
Display name:
Symantec Volume Change Tracking Driver

Service name:
VTrack

Type:
Kernel device driver (KernelDriver)

Group:
PnP Filter