gwfilt64.sys

Creative Labs Inc

Publisher:
Creative Technology Ltd.  (signed by Creative Labs Inc)

Description:
Creative Audio Driver

Version:
6.10.00.0003

MD5:
5b768585620e3f1792295a00cf802c00

SHA-1:
1765ddedc38d6dedf9f19e280853cc9fc1c7704c

SHA-256:
c355ad8555e136afcc9c129ff1c1028f16ccc4bdd48ae56a66d3c39dee1c0ced

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 1:32:11 PM UTC  (today)

File size:
51.1 KB (52,312 bytes)

Copyright:
Copyright © Creative Technology Ltd. 2008

File type:
Driver (Win64 SYS)

Language:
English (United Kingdom)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\{c5b26a6b-3b09-48c3-95e7-8aeae98a5a04}\gwfilt64.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/30/2006 1:00:00 AM

Valid to:
7/15/2009 12:59:59 AM

Subject:
CN=Creative Labs Inc, OU=CLI, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Creative Labs Inc, L=Milpitas, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
36336D836A19E244FF0E52882EB5B1DE

File PE Metadata
Compilation timestamp:
4/10/2008 9:20:29 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
768:p4V6EA5wGG02ExwdD18WLnkbpNmdMRAwhYRAKF:GV6uL02E+dx8WbApkdMqqYq8

Entry address:
0x5010

Entry point:
48, 53, 48, 83, EC, 20, 48, 8B, D9, E8, F2, BF, FF, FF, 48, 8B, 43, 30, 48, 8D, 0D, A7, F1, FF, FF, 4C, 8D, 1D, 60, F3, FF, FF, 48, 83, C3, 70, 4C, 89, 5B, F8, 48, 89, 48, 08, 48, 8D, 0D, 1D, F6, FF, FF, B8, 03, 00, 00, 00, 66, 66, 66, 90, 66, 66, 66, 90, 48, 89, 0B, 48, 89, 4B, 08, 48, 89, 4B, 10, 48, 83, C3, 40, 48, FF, C8, 48, 89, 4B, D8, 48, 89, 4B, E0, 48, 89, 4B, E8, 48, 89, 4B, F0, 48, 89, 4B, F8, 75, D8, 48, 89, 0B, 48, 89, 4B, 08, 48, 89, 4B, 10, 48, 89, 4B, 18, 48, 83, C4, 20, 5B, C3, 00, 00, 00...
 
[+]

Entropy:
6.6700

Code size:
15 KB (15,360 bytes)