rspsanity32.sys

Sanity Check

Daniel Terhell

It runs as a Windows file system device driver named “rspSanity”.
Publisher:
Resplendence Software Projects Sp.  (signed by Daniel Terhell)

Product:
Sanity Check

Description:
Resplendence Sanity Check

Version:
2.00 built by: WinDDK

MD5:
f26b95e45c7afed923000afa771d667f

SHA-1:
b88b86f188918e503eddaf9cbb942861c0f634a4

SHA-256:
7a6ab4f8719def1b683c7711b31944d4b09c1a826003491d8db2371dad11e601

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 3:52:44 PM UTC  (today)

File size:
26.6 KB (27,192 bytes)

Product version:
2.00

Copyright:
Copyright (c)1997-2009 Resplendence Software Projects Sp.

Original file name:
rspsanity.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\rspsanity32.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
7/10/2008 2:15:45 AM

Valid to:
7/10/2011 2:15:45 AM

Subject:
E=daniel@resplendence.com, CN=Daniel Terhell, C=IT

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000011B0A1BE928

File PE Metadata
Compilation timestamp:
11/12/2009 11:09:52 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
384:jXRPgHb0GuEnELuhIpkMRT2/VJk7htuF0sccRFO9ZYJLFReHNcdUb+MH:LRP3GuR55sko07cRFO90LMia

Entry address:
0x7146

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, C0, BA, FF, FF, CC, CC, D8, 71, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 26, 75, 00, 00, 30, 40, 00, 00, C8, 71, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 7C, 75, 00, 00, 20, 40, 00, 00, A8, 71, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 3E, 76, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 06, 76, 00, 00, E8, 75, 00, 00, CC, 75, 00, 00, B0, 75, 00, 00, 9A, 75, 00, 00, 84, 75, 00, 00, 2A, 76, 00, 00, 00, 00...
 
[+]

Code size:
12 KB (12,288 bytes)

Driver
Display name:
rspSanity

Description:
rspSanity filter

Type:
File system 'filter' driver (FileSystemDriver)

Group:
FSFilter Undelete

Depends on:
FltMgr


Scan rspsanity32.sys - Powered by Reason Core Security