SAGEFS4.sys

SageTech ERM 1.0

SageTech

It runs as a Windows file system device driver named “SageFs”.
Publisher:
SageTech Co.,Ltd  (signed by SageTech)

Product:
SageTech ERM 1.0

Description:
SageTech ERM 1.0 (SAGEFS4.sys)

Version:
4,50,25,12179

MD5:
dc7412b336c0cdb152d78c25315ca991

SHA-1:
79cd808c4edbee233507c590028329e84adae605

SHA-256:
ed5460c14becf52036a2a59274d5cad4954242078f0a271a3f6a137251e19af1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/28/2024 4:48:06 AM UTC  (today)

File size:
260.2 KB (266,488 bytes)

Product version:
4,50,25,12179

Copyright:
(C) SageTech Co.,Ltd. All rights reserved.

Original file name:
SAGEFS4.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\sagefs4.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/20/2008 8:00:00 AM

Valid to:
5/21/2011 7:59:59 AM

Subject:
CN=SageTech, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=SageTech, L=San Jose, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1DB75B5C053C3EA3D15F15F02166C6B4

File PE Metadata
Compilation timestamp:
1/6/2011 6:47:33 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.10

CTPH (ssdeep):
3072:5UaAoTxn4h341rARps00HuXuYmlEtFP3jgndNOpd5LAOXivuu/R/zFF05AfSmyEh:jMIuGNOpHFwhE/NzfpazINTbW

Entry address:
0x3BF43

Entry point:
8B, FF, 55, 8B, EC, A1, 44, 7E, 03, 00, 85, C0, B9, 40, BB, 00, 00, 74, 04, 3B, C1, 75, 23, 8B, 15, 10, 2D, 03, 00, B8, 44, 7E, 03, 00, C1, E8, 08, 33, 02, 25, FF, FF, 00, 00, A3, 44, 7E, 03, 00, 75, 07, 8B, C1, A3, 44, 7E, 03, 00, F7, D0, A3, 40, 7E, 03, 00, 5D, E9, 06, FA, FF, FF, CC, CC, DC, BF, 03, 00, 00, 00, 00, 00, 00, 00, 00, 00, 94, CA, 03, 00, 94, 2B, 02, 00, C8, BF, 03, 00, 00, 00, 00, 00, 00, 00, 00, 00, FE, CA, 03, 00, 80, 2B, 02, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.6586

Code size:
178.1 KB (182,400 bytes)

Driver
Display name:
SageFs

Description:
SageFs Filter Driver

Type:
File system 'filter' driver (FileSystemDriver)

Group:
FSFilter Activity Monitor


Scan SAGEFS4.sys - Powered by Reason Core Security