bnbasex.sys

Baidu Antivirus

Baidu Online Network Technology (Beijing)Co., Ltd

It runs as a Windows 64-bit kernel mode device driver named “Bnbase”.
Scan bnbasex.sys - Powered by Reason Core Security
Publisher:
Baidu, Inc.  (signed by Baidu Online Network Technology (Beijing)Co., Ltd)

Product:
Baidu Antivirus

Description:
Baidu Antivirus NetBase Driver

Version:
4,8,2,72044

MD5:
6b97f4a5441d95d08a5ebe53bf3cfee7

SHA-1:
fe8661dd3c83a1cfffaea227009a00b85de505bf

SHA-256:
e4172e7d07dd70dd3814ce98a7d7baf07312376463bb3593c645df84a5ea3aaf

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/8/2016 1:14:26 AM UTC  (today)

File size:
58.8 KB (60,224 bytes)

Product version:
4,8,2,72044

Copyright:
Copyright (C) 2013 Baidu, Inc. All rights reserved.

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\bnbasex.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/24/2012 2:00:00 AM

Valid to:
4/25/2015 1:59:59 AM

Subject:
CN="Baidu Online Network Technology (Beijing)Co., Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Baidu Online Network Technology (Beijing)Co., Ltd", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3BDB1994B98BBB19AB55A42337FA4F5C

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
768:rrcYyD8aOX0RocMLbZZS+d7Zqkd9sfXCMdzBZFFHpBa6gqioHN2vnD2XbhFYymo5:0a17Zqkd9FMdnFBAqiwN2vqXb7Oo5

Entry point:
55, 8B, EC, 81, EC, 5C, 04, 00, 00, 53, 56, C7, 45, FC, 00, 00, 00, 00, C6, 85, BB, FB, FF, FF, 00, 33, C0, 66, 89, 85, AC, FB, FF, FF, 33, C9, 89, 8D, AE, FB, FF, FF, 66, 89, 8D, B2, FB, FF, FF, C6, 85, CF, FB, FF, FF, 00, C6, 85, C3, FB, FF, FF, 00, 8B, 15, E0, 9A, 01, 00, 89, 95, B4, FB, FF, FF, B8, 1A, 00, 00, 00, 66, 89, 85, D0, FB, FF, FF, B9, 1C, 00, 00, 00, 66, 89, 8D, D2, FB, FF, FF, C7, 85, D4, FB, FF, FF, 20, 98, 01, 00, C7, 85, A4, FB, FF, FF, 00, 00, 00, 00, BA, 1E, 00, 00, 00, 66, 89, 55, D8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Driver
Display name:
Bnbase

Type:
Kernel device driver (KernelDriver)


Scan bnbasex.sys - Powered by Reason Core Security