plchw.sys

IBH SOFTEC GmbH

It runs as a Windows kernel mode device driver named “PLCHW”.
Publisher:
IBH SOFTEC GmbH  (signed and verified)

MD5:
edf97ffc011ad5f17e73adf55e91233c

SHA-1:
7db796a737aa336755d1c35406ba20fc3d3b2998

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 2:35:16 PM UTC  (today)

File size:
49.2 KB (50,352 bytes)

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\plchw.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/26/2010 5:00:00 AM

Valid to:
10/27/2011 4:59:59 AM

Subject:
CN=IBH SOFTEC GmbH, OU=Development, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=IBH SOFTEC GmbH, L=Michelstadt, S=Hessen, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
69340A16B843FBD70BD1CCE7F78B526F

File PE Metadata
Compilation timestamp:
1/3/1997 10:54:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
3.0

CTPH (ssdeep):
384:teqAT3Kib8R1LUHFb2CPVtfxsHXdvMQ7mhyGvMgQAY4djmBancMnPCv4g1T+9pIp:ciRxWd5tfOHeQMMrAY4diBh6sfLf1

Entry address:
0x10A0

Entry point:
55, 8B, EC, 83, EC, 58, 53, 56, 57, C7, 45, C4, 00, 00, 00, 00, BE, 24, 30, 01, 00, 8D, 7D, A8, B9, 07, 00, 00, 00, F3, A5, BE, 00, 30, 01, 00, 8D, 7D, D4, B9, 09, 00, 00, 00, F3, A5, 8D, 45, A8, 50, 8D, 45, CC, 50, FF, 15, 9C, 40, 01, 00, 8D, 45, C4, 50, 6A, 00, 6A, 00, 68, 00, 80, 00, 00, 8D, 45, CC, 50, 68, 04, 20, 00, 00, 8B, 45, 08, 50, FF, 15, A0, 40, 01, 00, 89, 45, C8, 83, 7D, C8, 00, 0F, 8C, 6E, 00, 00, 00, 8B, 45, 08, C7, 40, 70, 90, 11, 01, 00, 8B, 45, 08, 8B, 40, 70, 8B, 4D, 08, 89, 41, 40, 8B...
 
[+]

Entropy:
5.8631

Developed / compiled with:
Microsoft Visual C++

Code size:
2 KB (2,048 bytes)

Driver
Display name:
PLCHW

Type:
Kernel device driver (KernelDriver)


Scan plchw.sys - Powered by Reason Core Security