SbieDrv.sys

Sandboxie

SANDBOXIE L.T.D

It runs as a Windows kernel mode device driver named “SbieDrv”.
Publisher:
SANDBOXIE L.T.D  (signed and verified)

Product:
Sandboxie

Description:
Sandboxie Kernel Mode Driver

Version:
3.62

MD5:
6cdba7934a4f48c1606deb957ca30793

SHA-1:
5d3387dfe266b525a9b54464cbf1beff56a88d6b

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/26/2024 9:48:56 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Trojan.Win32.Injector
4.0.3.14320

File size:
122.9 KB (125,824 bytes)

Product version:
3.62

Copyright:
Copyright © 2004-2011 by Ronen Tzur

Original file name:
SbieDrv.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Program Files\sandboxie\sbiedrv.sys

Digital Signature
Signed by:

Authority:
Root Agency

Valid from:
1/1/2010 10:57:51 AM

Valid to:
1/1/2040 12:59:59 AM

Subject:
CN=SANDBOXIE L.T.D

Issuer:
CN=Root Agency

Serial number:
1CFE877A9155569F49A6ED5F8CFF133A

File PE Metadata
Compilation timestamp:
11/23/2011 2:16:19 PM

OS version:
5.2

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.10

CTPH (ssdeep):
3072:ijLkYdlEGiSl0QfPb3snS0vOSoIzL0EUxl/jTI2pTUhM:+s4NL3ESYoIX0Fxl/Y2+hM

Entry address:
0x1B844

Entry point:
55, 8B, EC, 8B, 45, 08, 53, 57, A3, 9C, AB, 02, 00, 33, FF, 89, 78, 34, E8, 89, FA, FF, FF, 8A, D8, 84, DB, 0F, 84, FB, 00, 00, 00, E8, 06, 0C, FF, FF, 3B, C7, A3, 98, A7, 02, 00, 75, 0E, 57, 57, 68, 50, 04, 01, C1, E8, A9, 6A, FF, FF, 32, DB, 84, DB, 0F, 84, D7, 00, 00, 00, E8, 38, 91, FE, FF, 8A, D8, 84, DB, 0F, 84, C8, 00, 00, 00, 56, 8B, 75, 0C, 6A, 01, FF, 76, 04, FF, 35, 98, A7, 02, 00, E8, FC, 6A, FF, FF, 3B, C7, A3, A0, AB, 02, 00, 75, 02, 32, DB, 84, DB, 0F, 84, A0, 00, 00, 00, 8B, C6, E8, FC, FA...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
108.5 KB (111,104 bytes)

Driver
Display name:
SbieDrv

Type:
Kernel device driver (KernelDriver)


Scan SbieDrv.sys - Powered by Reason Core Security