Gridinsoft Logo

The TrueSight.sys (Antirootkit module) File Analysis

Technical Analysis

File Name TrueSight.sys
File Type
Win32 EXE
Magic Bytes PE32+ executable (native) x86-64, for MS Windows
SSDEEP Hash
384:y3YUY30d1Kgf4AtcTmwZ/22a97C5ohYh3IB96Oys2+l0skiM0HMFrba8no0ceD/9:yOUkgfdZ9pRyv+uPzCMHo3q4tDghH
Scanner Version 1.0.192.174
Database Version 2024-10-11 13:00:27 UTC

Suspicious File Detected

Detected by 10 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
14%
Detection Rate
28,272
File Size (bytes)
10/72
Engines Detected
2024-10-11
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
0d5a09b08568760ae85a801fcbc0f83d
SHA1
3ec1e15b4a903b92e965a44dd9514267c1ceff80
SHA256
347acba74fdcbeac671521739f8a34ec0e378caf716c31f55616f9f843e4d0d3
SHA512
03aeba403c77793730006bd6d67e505c7dbff61e25bb1dd095b2274c22b30c145dde13764c27d062cc8ce2208761db88797af62c9650b3be56c2bc1cbef3a3c1
ImpHash
17fec1f996adceb4112879eb84986897

Security Engines with Detections (10 of 72)

Zillya
Trojan.Adlice.Win64.2 Malicious
huorong
Exploit/Vulndriver Malicious
Elastic
Windows.VulnDriver.TrueSight Malicious
ESET-NOD32
Win64/Adlice.C potentially unsafe Malicious
Rising
PUA.Adlice!8.18E32 (CLOUD) Malicious
Jiangmin
Exploit.TrueSight.a Malicious
Kingsoft
Win64.Troj.Adlice.C Malicious
Malwarebytes
Exploit.VulnerableDriver Malicious
Fortinet
Riskware/Adlice Malicious
DeepInstinct
MALICIOUS Malicious
62 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Image Base 0x00010000
Entry Point 0x0001816c
Compilation Time 2016-01-15 20:17:58
Checksum 0x00007adb (Actual: 0x00007adb)
OS Version 6.1
PEiD Signatures PE32+ executable (native) x86-64, for MS Windows
PDB Path c:\tools_git_priv\truesight\driver\objfre_win7_amd64\amd64\TrueSight.pdb
Digital Signature OK
Imports 1 libraries
ntoskrnl
Exports 0 functions
Resources 1 Resources
Sections 8 Sections

Version Information

CompanyName Adlice Software
FileDescription Antirootkit module
FileVersion 2.0.2
InternalName Truesight
LegalCopyright Copyright Adlice Software(C) 2014
LegalTrademarks1 Adlice Software
LegalTrademarks2 Adlice Software
OriginalFilename Truesight
ProductName Truesight
ProductVersion 2.0.2
Translation 0x040c 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 11,460 bytes 11,776 bytes 6.02 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ A1A6A61401EA2CB054171710192F6313
.rdata 0x00004000 1,708 bytes 2,048 bytes 4.28 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ 3C9E05A845F49ED5B61EA6E4BF4199C0
.data 0x00005000 512 bytes 512 bytes 1.56 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 53257B8F61EF0D2858125C02775FCDED
.pdata 0x00006000 420 bytes 512 bytes 3.47 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ 7636A215FD14F6AB68ACD03B6D2E4877
PAGE 0x00007000 108 bytes 512 bytes 1.31 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 3ED25ACDF64FD3F2AFF649E4D79FB3D3
INIT 0x00008000 2,070 bytes 2,560 bytes 4.69 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE B2ECFD3F1375A1AA2598D94A5B02E205
.rsrc 0x00009000 968 bytes 1,024 bytes 3.13 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ CCC45C302FA39BEFEA3F161810A1873D
.reloc 0x0000a000 150 bytes 512 bytes 0.96 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 7DF705B2879285C7DA7B4488BED158B0

Resource Analysis

Total Resources: 1 (868 bytes)
Resource Type Count Total Size Percentage
RT_VERSION 1 868 bytes
100%

Certificate Chain Analysis

Certificate Information
Product Truesight
Description Antirootkit module
File Version 2.0.2
Original Name Truesight
Signing Date 08:18 PM 01/15/2016 (3450 days ago)
Verification Status Signed
Signers Adlice; DigiCert High Assurance Code Signing CA-1; DigiCert
Counter Signers Symantec Time Stamping Services Signer - G4; Symantec Time Stamping Services CA - G2; Thawte Timestamping CA
Internal Name Truesight
Copyright Copyright Adlice Software(C) 2014
Certificate Chain Summary
Symantec Time Stamping Services CA - G2 #1 Primary
Validity Period: 2012-12-21 00:00:00 → 2020-12-30 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 7E 93 EB FB 7C C6 4E 59 EA 4B 9A 77 D4 06 FC 3B
Symantec Time Stamping Services Signer - G4 #2 Chain
Validity Period: 2012-10-18 00:00:00 → 2020-12-29 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 0E CF F4 38 C8 FE BF 35 6E 04 D8 6A 98 1B 1A 50
Adlice #3 Chain
Validity Period: 2015-03-31 00:00:00 → 2018-06-28 12:00:00
Signature Algorithm: sha1RSA
Serial Number: 06 E2 84 CD 38 EE 15 62 30 95 DC BD 38 E6 5F 9B
DigiCert High Assurance EV Root CA #4 Chain
Validity Period: 2011-04-15 19:45:33 → 2021-04-15 19:55:33
Signature Algorithm: sha1RSA
Serial Number: 61 20 4D B4 00 00 00 00 00 27
DigiCert High Assurance Code Signing CA-1 #5 Chain
Validity Period: 2011-02-11 12:00:00 → 2026-02-10 12:00:00
Signature Algorithm: sha1RSA
Serial Number: 02 C4 D1 E5 8A 4A 68 0C 56 8D A3 04 7E 7E 4D 5F

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
10 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware