ewf.sys

Windows Embedded Standard 7

Microsoft Corporation

It runs as a Windows 64-bit kernel mode device driver named “Ewf”. It is installed with Windows 7 as a General Distribution Release (GDR) as part of a Hotfix.
Publisher:
Microsoft Corporation  (signed and verified)

Product:
Windows® Embedded Standard 7

Description:
Enhanced Write Filter Driver

 
Part of the Windows 7 (with Service Pack 1) Operating System

Version:
1.0.0331.0 (win7sp1_gdr.110715-1504)

MD5:
fc574ce60bd9a23b3ba125935641e4f1

SHA-1:
8350ca2568bcca99ba0d471be6ea85c08ce91be7

SHA-256:
fd98c19c4ef4a164db0360aae0c64228f696619de6c2054906e3dcd546343f6f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/26/2024 6:26:29 AM UTC  (today)

File size:
68.4 KB (70,016 bytes)

Product version:
1.0.0331.0

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
ewf.sys

File type:
Driver (Win64 SYS)

Common path:
C:\Windows\System32\drivers\ewf.sys

Digital Signature
Authority:
Microsoft Corporation

Valid from:
2/15/2011 5:11:44 AM

Valid to:
5/15/2012 5:11:44 AM

Subject:
CN=Microsoft Windows, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Windows Verification PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
61030556000000000010

File PE Metadata
Compilation timestamp:
7/16/2011 10:55:19 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
1536:/ac6IdRQfFjXbTS8BfLt/9TxgXENaRvEQg:/w9HeCh/teXENY8Qg

Entry address:
0x1128C

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, 5E, FD, FF, FF, CC, CC, D8, 12, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, A0, 1C, 01, 00, 00, E0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 15, 01, 00, 00, 00, 00, 00, 98, 15, 01, 00, 00, 00, 00, 00, AC, 15, 01, 00, 00, 00, 00, 00, C2, 15, 01, 00, 00, 00, 00, 00, DA, 15, 01, 00, 00, 00, 00, 00, FA, 15, 01, 00, 00, 00, 00, 00, 10, 16, 01, 00...
 
[+]

Entropy:
6.4653

Code size:
54.5 KB (55,808 bytes)

Driver
Display name:
Ewf

Type:
Kernel device driver (KernelDriver)