swenum.sys

Windows Main Build Lab Account

It runs as a Windows kernel mode device driver named “Software Bus Driver”.
Publisher:
Windows Main Build Lab Account  (signed and verified)

MD5:
a6d284574382a70a0cfa31edde60c91d

SHA-1:
9feb007220fbf5aec08d69bfbc2be911650d9fc3

SHA-256:
47111e8e865105f97b33b2d1e9109d6ee68be9ca4c65a643e07ac6f1ae87b3fd

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/6/2024 3:31:14 AM UTC  (today)

File size:
9.1 KB (9,312 bytes)

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\swenum.sys

Digital Signature
Authority:
MSIT Test CodeSign CA 2

Valid from:
3/13/2009 1:39:14 AM

Valid to:
3/13/2010 12:39:14 AM

Subject:
CN=Windows Main Build Lab Account

Issuer:
CN=MSIT Test CodeSign CA 2, DC=redmond, DC=corp, DC=microsoft, DC=com

Serial number:
29C9F976000100003536

File PE Metadata
Compilation timestamp:
4/8/2009 8:05:47 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
96:OLwF92Mr/puZW2WZw+DWwiEODPDfWUDaDlCmqDPDfGWQDaDhQAdijFP2S+lczQJ5:qwxr52WZw+DW/ETpXbWiAGFbECIT/NyY

Entry address:
0xB96

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 60, FF, FF, FF, CC, CC, 08, 0C, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, A6, 0C, 00, 00, A4, 06, 00, 00, E4, 0B, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 94, 0D, 00, 00, 80, 06, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B4, 0C, 00, 00, 7A, 0D, 00, 00, 5E, 0D, 00, 00, 42, 0D, 00, 00, 22, 0D, 00, 00, 08, 0D, 00, 00, EA, 0C, 00, 00, CC, 0C, 00, 00, 00, 00, 00, 00, 98, 0C, 00, 00, 82, 0C, 00, 00, 72, 0C, 00, 00, 62, 0C...
 
[+]

Entropy:
5.9689

Code size:
1.8 KB (1,792 bytes)

Driver
Display name:
Software Bus Driver

Service name:
swenum

Type:
Kernel device driver (KernelDriver)


Scan swenum.sys - Powered by Reason Core Security