cpwfpnd.sys

cpwfpnd.sys

Nord Net

Publisher:
NordNet  (signed by Nord Net)

Product:
cpwfpnd.sys

Description:
WFP driver

Version:
2.3.3.2

MD5:
84b256849e16e9c7d1c7a4ccd9f57153

SHA-1:
d54a5a9979292187211ae3bdf8ed2927d02bca1a

SHA-256:
7a89fd3493d15a0a3174970938f78a6f03b59e6cf5216d945471d871f0306ebb

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/24/2024 10:35:46 PM UTC  (today)

Scan engine
Detection
Engine version

Trend Micro House Call
Suspicious_GEN.F47V0302
7.2.21

File size:
31.2 KB (31,928 bytes)

Product version:
2.3.3.2

Copyright:
NordNet (c) 2015

Original file name:
cpwfpnd.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Program Files\contrôle parental orange\cpwfpnd.sys

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
12/16/2013 1:00:00 AM

Valid to:
3/18/2015 12:59:59 AM

Subject:
CN=Nord Net, O=Nord Net, L=Hem, S=Nord, C=FR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
198A0EF0BC1C8A044B3DD424D6B8ABBF

File PE Metadata
Compilation timestamp:
3/2/2015 8:35:34 AM

OS version:
6.2

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
11.0

CTPH (ssdeep):
384:13esF+/+WqG9oW/4Wdk5HetdX5+Ht1hAZCFHxZz7YGFZtMSF8cUFx3HO0BevuY8l:1uS+GW/4s75+N1hAeRqFL5Fx3HPl

Entry address:
0x53E6

Entry point:
8B, FF, 55, 8B, EC, E8, 16, 3C, 00, 00, 5D, E9, 70, D3, FF, FF, CC, CC, CC, CC, CC, CC, 3B, 0D, 00, 70, 40, 00, 75, 03, C2, 00, 00, E9, 06, 00, 00, 00, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 51, 89, 4D, FC, 6A, 02, 59, CD, 29, CC, CC, CC, CC, CC, CC, CC, CC, B8, 01, 00, 00, 00, C2, 10, 00, 5C, 00, 00, 00, 61, 00, 70, 00, 70, 00, 54, 00, 61, 00, 62, 00, 6C, 00, 65, 00, 00, 00, 69, 00, 70, 00, 54, 00, 61, 00, 62, 00, 6C, 00, 65, 00, 00, 00, 70, 00, 6F, 00, 72, 00, 74, 00, 54, 00, 61, 00, 62, 00, 6C, 00...
 
[+]

Code size:
20 KB (20,480 bytes)

Scan cpwfpnd.sys - Powered by Reason Core Security