ldsecdrv.sys

LANDESK Software

LANDesk Software, Inc.

It runs as a Windows file system device driver named “LDSecDrv”.
Publisher:
LANDESK Software, Inc. and its affiliates.  (signed by LANDesk Software, Inc.)

Product:
LANDESK Software

Description:
LANDesk HIPS Driver

Version:
9.60.4.76

MD5:
f0f417f291b3e6a602c771633e96507c

SHA-1:
a39c1cded95af9fa8547e0b0aa63b3a8271b7bc8

SHA-256:
6643b6e3fb58f1c3ac59fc5a8add9e6237702893fda1fd79d8f1ae0a5048f707

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 5:46:39 PM UTC  (today)

File size:
254.8 KB (260,912 bytes)

Product version:
9.60.4.76

Copyright:
Copyright © 2014 LANDESK Software, Inc. and its affiliates.

Original file name:
virblock.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\ldsecdrv.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/6/2014 8:00:00 AM

Valid to:
11/14/2017 7:59:59 AM

Subject:
CN="LANDesk Software, Inc.", O="LANDesk Software, Inc.", L=South Jordan, S=Utah, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
04E7F852193763C520A1A94220CD2DF8

File PE Metadata
Compilation timestamp:
11/5/2015 10:04:25 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
11.0

CTPH (ssdeep):
6144:rsBcIgyLe8CzedrC45O2AjQ0/u53xl+ItBI:rr2AjIl+Is

Entry address:
0x3C000

Entry point:
55, 8B, EC, 83, EC, 0C, 33, C0, 68, C0, B9, 04, 00, 68, 8C, F3, 03, 00, 68, C4, A1, 04, 00, A3, C0, B9, 04, 00, A3, C4, B9, 04, 00, A3, C8, B9, 04, 00, E8, 65, 39, FD, FF, 68, C4, B9, 04, 00, 68, A0, F3, 03, 00, 68, C4, A1, 04, 00, E8, 51, 39, FD, FF, 68, C8, B9, 04, 00, 68, B8, F3, 03, 00, 68, C4, A1, 04, 00, E8, 3D, 39, FD, FF, 83, 3D, C0, B9, 04, 00, 00, 74, 35, E8, 6F, 05, FD, FF, 85, C0, 79, 2C, C7, 45, F4, 81, 00, 00, 00, 8B, 4D, F4, 84, C9, 8B, 0D, C0, B9, 04, 00, 79, 05, 83, F9, 01, 74, 05, 83, F9...
 
[+]

Entropy:
6.8086

Developed / compiled with:
Microsoft Visual C++

Code size:
172.5 KB (176,640 bytes)

Driver
Display name:
LDSecDrv

Type:
File system 'filter' driver (FileSystemDriver)

Group:
FSFilter Content Screener

Depends on:
FltMgr


Scan ldsecdrv.sys - Powered by Reason Core Security