96ew.sys

Futime Manufacturing Ltd

It runs as a Windows kernel mode device driver named “96EW Filter”.
Publisher:
Futime Manufacturing Ltd  (signed and verified)

MD5:
9caf0f842758b5eb83e4623b87ab70ae

SHA-1:
01e609560d7627eef0272da8a309dc5e4c3c7dc5

SHA-256:
d5727edf26fa97b87b72a05495d01e2e3ea51793ecc90b98fc74d07fee0522a9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/11/2024 1:07:54 AM UTC  (today)

File size:
29 KB (29,688 bytes)

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\96ew.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/8/2010 3:00:00 AM

Valid to:
6/9/2011 2:59:59 AM

Subject:
CN=Futime Manufacturing Ltd, OU=Marketing Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Futime Manufacturing Ltd, L=Shenzhen, S=Guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
393F9E76807B9BB28A829ACBFE5DD81F

File PE Metadata
Compilation timestamp:
10/29/2010 9:02:21 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.10

CTPH (ssdeep):
384:zlInF8B9YwnmXi59K/8W26sNKnZNHvTGPr6nlnpg/daHHHHHHHHHHHdky8NuVQz7:zp9YbS5031X2N7BnuLWMmjbCGlJF

Entry address:
0x4DE

Entry point:
E9, AD, 00, 00, 00, CC, 8B, 44, 24, 04, 8B, 40, 0A, 2D, 03, 06, E3, 05, 74, 18, 48, 48, 74, 14, 2D, 00, 00, 17, 14, 74, 0D, 2D, FE, 00, 00, 00, 74, 06, 8B, 44, 24, 08, EB, 03, 6A, 07, 58, C2, 08, 00, 8B, 44, 24, 04, 8B, 48, 0A, 81, E9, 03, 06, E3, 05, 74, 18, 49, 49, 74, 14, 81, E9, 00, 00, 17, 14, 74, 0C, 81, E9, FE, 00, 00, 00, 74, 04, 32, C0, EB, 35, 33, C9, 6A, 07, 89, 48, 0E, C6, 40, 12, 01, C6, 40, 13, 02, C6, 40, 14, 0C, C6, 40, 15, 01, 88, 48, 16, 88, 48, 1D, 88, 48, 1E, 88, 48, 1F, 83, C0, 21, 5A...
 
[+]

Packer / compiler:
Xtreme-Protector v1.05

Code size:
18.3 KB (18,688 bytes)

Driver
Display name:
96EW Filter

Service name:
96EW

Type:
Kernel device driver (KernelDriver)

Group:
Extended Base


Scan 96ew.sys - Powered by Reason Core Security