mutenx.sys

IBIK, LLC

It runs as a Windows kernel mode device driver named “MUTENX_SERVICE”.
Publisher:
IBIK, LLC  (signed and verified)

Description:
kernel module

Version:
0, 0, 0, 10

MD5:
a813ac39ce97c98b9a3bd4a18e8234b3

SHA-1:
4ff58c6b9e048478d47cff94712e5f4b0fe62119

SHA-256:
6b98bebf98eb2cbaa3303272adc07cb73a2a0a44eb2448f44c3880d9dc3c9855

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/11/2016 11:20:16 PM UTC  (ten months ago)

Scan engine
Detection
Engine version

ByteHero BDV
Trojan.Win32.Native.Heur.Gen
5.9.2016.10

File size:
57 KB (58,400 bytes)

Product version:
0, 1, 0, 0

File type:
Driver (Win32 SYS)

Language:
Language Neutral

Common path:
C:\Windows\System32\drivers\mutenx.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
11/22/2013 6:21:37 PM

Valid to:
11/23/2014 6:21:37 PM

Subject:
CN="IBIK, LLC", O="IBIK, LLC", L=Moscow, S=Moscow, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121EC63DE53EC2C8DE7D552E8CF8DA03676

File PE Metadata
Compilation timestamp:
7/14/2014 12:09:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
768:ROIVXh0MrQgCCDUgbocRAofXIW+dCd6JUp4rOagsnejmNLWIcp45Iw+w6BRg4q:gIVeMdU4aY/4AagGLWbp4tsW

Entry address:
0x1CA7

Entry point:
8B, 0D, 38, 12, 01, 00, 33, C0, 39, 01, 56, 75, 4F, 8B, 74, 24, 08, 68, D8, B8, 01, 00, 50, 68, 00, 01, 00, 00, 6A, 22, 68, 0C, B0, 01, 00, 50, 56, 89, 35, DC, B8, 01, 00, FF, 15, 3C, 12, 01, 00, 85, C0, 75, 27, A1, D8, B8, 01, 00, 83, 48, 1C, 04, C7, 46, 38, 49, 1C, 01, 00, C7, 46, 40, 7A, 1C, 01, 00, C7, 46, 70, F8, 1B, 01, 00, E8, C0, 3C, 00, 00, 33, C0, EB, 05, B8, 01, 00, 00, C0, 5E, C2, 08, 00, 8B, 54, 24, 08, 33, C0, 85, D2, 74, 49, 8B, 4C, 24, 04, 56, 8D, 34, 11, 0F, B7, 11, 85, D2, 74, 39, 03, C2...
 
[+]

Entropy:
6.6710

Code size:
43 KB (44,032 bytes)

Driver
Display name:
MUTENX_SERVICE

Type:
Kernel device driver (KernelDriver)


Scan mutenx.sys - Powered by Reason Core Security