pssnap.sys

pssnap Application

Paramount Software UK Ltd

It runs as a Windows kernel mode device driver named “Paramount Software Snapshot Filter”.
Publisher:
Macrium Software  (signed by Paramount Software UK Ltd)

Product:
pssnap Application

Description:
Backup image protection

Version:
5, 0, 4094, 0

MD5:
f7c8f8d613447d3c53814d69cda1f3de

SHA-1:
128e080c190c4bebeece992bfb70d8d5deaf7c18

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 7:44:59 AM UTC  (today)

File size:
15.6 KB (16,024 bytes)

Product version:
5, 0, 4094, 0

Copyright:
Copyright (C) 2008 Paramount Software UK Ltd

Original file name:
pssnap.exe

File type:
Driver (Win32 SYS)

Language:
English (United Kingdom)

Common path:
C:\Windows\System32\drivers\pssnap.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/8/2010 11:36:13 AM

Valid to:
11/8/2013 11:36:10 AM

Subject:
CN=Paramount Software UK Ltd, O=Paramount Software UK Ltd, L=Manchester, S=Greater Manchester, C=GB

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012C2C8AD4A2

File PE Metadata
Compilation timestamp:
10/30/2011 4:59:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

Entry address:
0x4000

Entry point:
56, 8B, 74, 24, 0C, 66, 8B, 06, 66, 05, 02, 00, 57, 66, A3, 12, 30, 01, 00, 0F, B7, C0, 68, 44, 64, 6B, 20, 50, 6A, 01, FF, 15, 08, 10, 01, 00, 85, C0, A3, 14, 30, 01, 00, 74, 0E, 56, 68, 10, 30, 01, 00, FF, 15, 54, 10, 01, 00, EB, 10, 66, 83, 25, 10, 30, 01, 00, 00, 66, 83, 25, 12, 30, 01, 00, 00, 8B, 54, 24, 0C, 8D, 72, 38, 6A, 1C, 59, B8, 56, 13, 01, 00, 8B, FE, F3, AB, B8, B2, 13, 01, 00, 89, 42, 78, 89, 42, 5C, 8B, 42, 18, C7, 06, 00, 20, 01, 00, C7, 42, 48, D0, 13, 01, 00, C7, 42, 70, 4B, 11, 01, 00...
 
[+]

Entropy:
6.3795

Code size:
4.5 KB (4,608 bytes)

Driver
Display name:
Paramount Software Snapshot Filter

Service name:
pssnap

Type:
Kernel device driver (KernelDriver)

Group:
PnP Filter


Scan pssnap.sys - Powered by Reason Core Security