| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
| Compilation Date | 2025-Sep-12 11:00:18 |
| Detected languages |
English - United States
|
| Debug artifacts |
D:\BambooBuild\VULSDK-VS-JOB1\Bin\VS2019\x64\Release\vlflt.pdb
|
| CompanyName | Bitdefender |
| FileDescription | vlflt Filter Driver |
| FileVersion | 2.0.269.0 |
| InternalName | vlflt.sys |
| LegalCopyright | Copyright © Bitdefender |
| OriginalFilename | vlflt.sys |
| ProductName | Bitdefender |
| ProductVersion | 2.0.269.0 |
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Suspicious | The PE is possibly packed. | Unusual section name found: PAGE |
| Suspicious | The PE contains functions most legitimate programs don't use. |
Functions which can be used for anti-debugging purposes:
|
| Info | The PE is digitally signed. |
Signer: Microsoft Windows Hardware Compatibility Publisher
Issuer: Microsoft Windows Third Party Component CA 2012 |
| Safe | VirusTotal score: 0/65 (Scanned on 2025-12-09 13:59:25) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 9 |
| TimeDateStamp | 2025-Sep-12 11:00:18 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x75e00 |
| SizeOfInitializedData | 0xf9200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000167300 (Section: INIT) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | A.0 |
| ImageVersion | A.0 |
| SubsystemVersion | 6.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x174000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x1636d9 |
| Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_FORCE_INTEGRITY
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| FLTMGR.SYS |
FltSupportsStreamContexts
FltReleaseContext FltGetStreamHandleContext FltGetStreamContext FltSupportsStreamHandleContexts FltSendMessage FltGetVolumeInstanceFromName FltGetFileNameInformationUnsafe FltObjectDereference FltReleaseFileNameInformation FltGetFileSystemType FltGetVolumeFromFileObject FltRetrieveIoPriorityInfo FltGetRoutineAddress FltClose FltCreateFileEx FltGetRequestorProcess FltDeleteStreamHandleContext FltQueryInformationFile FltAllocateContext FltGetVolumeName FltGetVolumeProperties FltAllocateGenericWorkItem FltOpenVolume FltObjectReference FltDeletePushLock FltGetVolumeGuidName FltSetStreamHandleContext FltReferenceContext FltInitializePushLock FltFsControlFile FltQueryVolumeInformation FltSetInstanceContext FltSetStreamContext FltGetDiskDeviceObject FltFreeGenericWorkItem FltReleasePushLock FltAcquirePushLockExclusive FltGetInstanceContext FltFindExtraCreateParameter FltGetFileNameInformation FltGetEcpListFromCallbackData FltIsEcpFromUserMode FltCancelFileOpen FltParseFileNameInformation FltGetDestinationFileNameInformation FltGetRequestorSessionId FltGetTransactionContext FltSetCallbackDataDirty FltAcquirePushLockShared FltCancellableWaitForSingleObject FltSetEcpListIntoCallbackData FltIsEcpAcknowledged FltFreeExtraCreateParameter FltAllocateExtraCreateParameter FltInsertExtraCreateParameter FltFreeExtraCreateParameterList FltAllocateExtraCreateParameterList FltUnregisterFilter FltRegisterFilter FltStartFiltering FltDeleteContext FltEnlistInTransaction FltSetTransactionContext FltIsVolumeSnapshot FltAcknowledgeEcp FltCreateFileEx2 FltEnumerateInstances FltCloseClientPort FltBuildDefaultSecurityDescriptor FltCreateCommunicationPort FltCloseCommunicationPort FltFreeSecurityDescriptor FltIsOperationSynchronous FltQueueGenericWorkItem |
|---|---|
| cng.sys |
BCryptGetProperty
BCryptOpenAlgorithmProvider BCryptFinishHash BCryptCloseAlgorithmProvider BCryptDestroyHash BCryptHashData BCryptCreateHash BCryptEncrypt BCryptDecrypt BCryptSetProperty BCryptDestroyKey BCryptImportKey BCryptExportKey BCryptGenerateSymmetricKey |
| ntoskrnl.exe |
RtlCompareUnicodeStrings
RtlUpperChar strncmp wcsncmp RtlUpcaseUnicodeChar _purecall PsRemoveLoadImageNotifyRoutine KeGetCurrentIrql PsSetLoadImageNotifyRoutine _vsnwprintf_s EtwWrite MmDoesFileHaveUserWritableReferences __C_specific_handler ExReleaseFastMutex KeWaitForMultipleObjects ObfDereferenceObject ExInitializePagedLookasideList PsCreateSystemThread ExDeletePagedLookasideList KeSetEvent KeInitializeSemaphore PsThreadType ObReferenceObjectByHandle KeReleaseSemaphore ExAcquireFastMutex ExFreePoolWithTag KeQueryActiveProcessorCount KeInitializeEvent KeWaitForSingleObject ZwClose PsTerminateSystemThread IoFileObjectType ObfReferenceObject ExpInterlockedPopEntrySList ExpInterlockedPushEntrySList ExQueryDepthSList IoAllocateWorkItem RtlAnsiStringToUnicodeString ZwQuerySystemInformation RtlFreeUnicodeString PsProcessType ExWaitForRundownProtectionRelease ExInitializeRundownProtection RtlInitAnsiString RtlGetVersion ExAcquireRundownProtection MmGetSystemRoutineAddress IoFreeWorkItem IoQueueWorkItem ExReleaseRundownProtection RtlImageDirectoryEntryToData MmUnmapViewInSystemSpace KeEnterCriticalRegion FsRtlGetFileSize MmMapViewInSystemSpace ZwQueryVirtualMemory IoGetCurrentProcess RtlWalkFrameChain _stricmp SeLocateProcessImageName FsRtlCreateSectionForDataScan RtlCompareMemory KeLeaveCriticalRegion IoGetStackLimits IoThreadToProcess PsGetCurrentThreadId ZwQueryKey ObDereferenceObjectDeferDelete ObQueryNameString ExDeleteResourceLite ExAcquireResourceExclusiveLite RtlInitUnicodeString IoVolumeDeviceToDosName IoOpenDeviceRegistryKey ExAcquireResourceSharedLite IoGetDeviceAttachmentBaseRef IoBuildDeviceIoControlRequest IoGetDevicePropertyData IoGetDeviceObjectPointer ExReleaseResourceLite KeClearEvent IoRegisterPlugPlayNotification IofCallDriver IoBuildSynchronousFsdRequest InitializeSListHead KeResetEvent ExInitializeResourceLite RtlValidSid SeQueryInformationToken RtlCompareUnicodeString RtlEnumerateEntryHashTable RtlEndEnumerationHashTable RtlHashUnicodeString RtlCreateHashTable PsGetProcessId PsInitialSystemProcess RtlRemoveEntryHashTable RtlInitEnumerationHashTable RtlInsertEntryHashTable RtlGetNextEntryHashTable RtlLookupEntryHashTable RtlDeleteHashTable KeStackAttachProcess KeUnstackDetachProcess MmSectionObjectType ObCloseHandle ObOpenObjectByPointer PsLookupProcessByProcessId PsReferenceProcessFilePointer PsGetProcessCreateTimeQuadPart RtlLengthSid RtlAppendUnicodeStringToString RtlPrefixUnicodeString KeAreAllApcsDisabled RtlStringFromGUID RtlEqualUnicodeString PsGetProcessPeb ExRegisterCallback ExCreateCallback ZwQueryInformationProcess ZwQueryInformationThread PsRemoveCreateThreadNotifyRoutine PsSetCreateProcessNotifyRoutineEx ZwOpenThread PsSetCreateThreadNotifyRoutine ExUnregisterCallback ProbeForRead IoGetAttachedDeviceReference ProbeForWrite ExDeleteNPagedLookasideList IoDeleteDevice RtlVerifyVersionInfo RtlQueryRegistryValues IoUnregisterPlugPlayNotificationEx ExInitializeNPagedLookasideList IoCreateDevice ZwQueryValueKey VerSetConditionMask IoWMIRegistrationControl InitSafeBootMode MmIsDriverVerifyingByAddress IoRegisterBootDriverReinitialization ZwOpenKey PsIsSystemThread PsGetProcessExitStatus PsLookupThreadByThreadId PsGetThreadProcess RtlLengthSecurityDescriptor PsGetCurrentProcessId RtlDowncaseUnicodeString towupper MmUnlockPages IoCancelIrp IoFreeIrp FsRtlCancellableWaitForMultipleObjects IoGetRelatedDeviceObject PsDereferencePrimaryToken ZwQueryInformationTransaction IoFreeMdl PsReferencePrimaryToken IoAllocateIrp PsReferenceImpersonationToken ZwTerminateProcess PsDereferenceImpersonationToken EtwUnregister EtwRegister ObUnRegisterCallbacks ObRegisterCallbacks ObGetObjectSecurity RtlSubAuthoritySid RtlGetSaclSecurityDescriptor IoQueryVolumeInformation RtlSubAuthorityCountSid PsGetProcessSessionId ObReleaseObjectSecurity PsGetProcessImageFileName PsGetThreadTeb IoGetTransactionParameterBlock RtlFindAceByType ExTryToAcquireFastMutex RtlAppendUnicodeToString CmUnRegisterCallback CmRegisterCallbackEx NtClose KeSetTimer KeInitializeDpc KeRemoveQueueDpc KeInitializeTimer KeCancelTimer KeFlushQueuedDpcs RtlInitializeSid IoQueryFileDosDeviceName RtlLengthRequiredSid ExAllocatePoolWithQuotaTag ExAllocatePoolWithTag IoGetTopLevelIrp KeBugCheckEx strcmp |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.0.269.0 |
| ProductVersion | 2.0.269.0 |
| FileFlags |
VS_FF_PRIVATEBUILD
|
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DRV
|
| FileSubtype | VFT2_DRV_SYSTEM |
| Language | English - United States |
| CompanyName | Bitdefender |
| FileDescription | vlflt Filter Driver |
| FileVersion (#2) | 2.0.269.0 |
| InternalName | vlflt.sys |
| LegalCopyright | Copyright © Bitdefender |
| OriginalFilename | vlflt.sys |
| ProductName | Bitdefender |
| ProductVersion (#2) | 2.0.269.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Sep-12 11:00:18 |
| Version | 0.0 |
| SizeofData | 87 |
| AddressOfRawData | 0x127298 |
| PointerToRawData | 0x125e98 |
| Referenced File | D:\BambooBuild\VULSDK-VS-JOB1\Bin\VS2019\x64\Release\vlflt.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Sep-12 11:00:18 |
| Version | 0.0 |
| SizeofData | 4 |
| AddressOfRawData | 0x1272f0 |
| PointerToRawData | 0x125ef0 |
| Size | 0x138 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14012e000 |
| GuardCFCheckFunctionPointer | 5369047312 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0x54927246 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (29395) | 6 |
| C objects (29395) | 8 |
| Imports (29395) | 7 |
| Total imports | 304 |
| C objects (LTCG) (30151) | 96 |
| Resource objects (30151) | 1 |
| 151 | 1 |
| Linker (30151) | 1 |
No comments yet.