GUMHFilter.sys

Glarysoft

Glarysoft LTD

It runs as a Windows file system device driver named “GUMHFilters”.
Publisher:
Glarysoft LTD  (signed and verified)

Product:
Glarysoft

Description:
GUMHFilter Driver

Version:
1.0.0.2

MD5:
642e8553bfc5e79b8d2023d9acf05246

SHA-1:
4f88af3e45ac79fb3a7d85d449258d3b2372d394

SHA-256:
04e9e9898ed89ed7f7fe65eaaa76e86709ec44ecdce419dbd6ca992cf8980989

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/23/2024 4:24:33 PM UTC  (today)

File size:
34.8 KB (35,640 bytes)

Product version:
1.0.0.2

Copyright:
Copyright (c) 2003-2016 Glarysoft Ltd

Original file name:
GUMHFilter.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Program Files\glarysoft\malware hunter\native\winxp_x86\gumhfilter.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/21/2016 3:00:00 AM

Valid to:
1/2/2019 2:59:59 AM

Subject:
CN=Glarysoft LTD, O=Glarysoft LTD, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2051DD6C5D5A858EBA1974D70B224A2F

File PE Metadata
Compilation timestamp:
9/26/2016 5:32:45 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
384:SPP7buF8tSjA4Kl4dvh3XgWcxsIDJXcn6onYPLptUHeMLgxu9OU+wAHKnB:QP7+6SU4KMY11cn6o/gx6wOB

Entry address:
0x3D37

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 3F, FF, FF, FF, CC, 10, 3E, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, E8, 41, 00, 00, F8, 09, 00, 00, 08, 3E, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 0A, 42, 00, 00, F0, 09, 00, 00, 98, 3D, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 9E, 44, 00, 00, 80, 09, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 74, 44, 00, 00, 5E, 44, 00, 00, 46, 44, 00, 00, 32, 44, 00, 00, 1E, 44, 00, 00, FA, 43, 00, 00, DC, 43, 00, 00, C0, 43, 00...
 
[+]

Entropy:
6.4184

Code size:
10.8 KB (11,008 bytes)

Driver
Display name:
GUMHFilters

Type:
File system 'filter' driver (FileSystemDriver)


Scan GUMHFilter.sys - Powered by Reason Core Security