| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
| Compilation Date | 2035-Aug-11 15:16:50 |
| Detected languages |
English - United States
|
| Debug artifacts |
qwavedrv.pdb
|
| CompanyName | Microsoft Corporation |
| FileDescription | Microsoft Quality Windows Audio Video Experience (qWave) Support Driver |
| FileVersion | 10.0.26100.7705 (WinBuild.160101.0800) |
| InternalName | qwavedrv.sys |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | qwavedrv.sys |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 10.0.26100.7705 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: fothk
Unusual section name found: PAGE Unusual section name found: GFIDS |
| Suspicious | The PE contains functions most legitimate programs don't use. |
Uses Windows's Native API:
|
| Safe | VirusTotal score: 0/67 (Scanned on 2026-03-09 07:37:04) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 11 |
| TimeDateStamp | 2035-Aug-11 15:16:50 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xd000 |
| SizeOfInitializedData | 0x8000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000012010 (Section: INIT) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | A.0 |
| ImageVersion | A.0 |
| SubsystemVersion | A.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x16000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0x24506 |
| Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x40000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ntoskrnl.exe |
RtlRecordFeatureUsage
RtlArmFeatureUsageProviderFlushNotification RtlQueryFeatureConfigurationChangeStamp RtlQueryFeatureConfiguration RtlRegisterFeatureConfigurationChangeNotification RtlUnregisterFeatureConfigurationChangeNotification RtlRegisterFeatureUsageProvider RtlUnregisterFeatureUsageProvider RtlInitUnicodeString IoDeleteDevice KeInitializeSpinLock IofCompleteRequest KeAcquireInStackQueuedSpinLock KeReleaseInStackQueuedSpinLock ExFreePoolWithTag RtlGetDaclSecurityDescriptor RtlMapGenericMask IoGetFileObjectGenericMapping SeCaptureSubjectContext SeLockSubjectContext SeAccessCheck SeUnlockSubjectContext SeReleaseSubjectContext __C_specific_handler RtlNotifyFeatureUsage ObfDereferenceObject MmUnlockPages IoFreeMdl KeAcquireInStackQueuedSpinLockAtDpcLevel KeReleaseInStackQueuedSpinLockFromDpcLevel IoReleaseCancelSpinLock IoIs32bitProcess ExAllocatePool2 PsGetCurrentProcessId PsGetCurrentThreadId ProbeForWrite IoAllocateMdl MmProbeAndLockPages MmMapLockedPagesSpecifyCache ObReferenceObjectByHandle IoFileObjectType RtlCompareUnicodeString IoAcquireCancelSpinLock IoGetCurrentProcess KeAttachProcess ObOpenObjectByPointer KeDetachProcess PsGetCurrentProcess RtlLengthRequiredSid RtlLengthSid SeExports RtlCreateAcl RtlAddAccessAllowedAce RtlCreateSecurityDescriptor RtlSetDaclSecurityDescriptor RtlSetOwnerSecurityDescriptor NtSetSecurityObject ZwClose MmGetSystemRoutineAddress IoCreateDevice IoDeviceObjectType ZwSetSecurityObject IoIsWdmVersionAvailable RtlAbsoluteToSelfRelativeSD wcschr ExAllocatePoolWithTag _wcsnicmp RtlLengthSecurityDescriptor _snwprintf SeCaptureSecurityDescriptor RtlGetSaclSecurityDescriptor RtlGetOwnerSecurityDescriptor RtlGetGroupSecurityDescriptor RtlFreeUnicodeString ZwCreateKey ZwQueryValueKey ZwSetValueKey ZwOpenKey ProbeForRead |
|---|
| QWAVE driver |
| Quality Windows Audio/Video Experience component driver |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 10.0.26100.7705 |
| ProductVersion | 10.0.26100.7705 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DRV
|
| FileSubtype | VFT2_DRV_SYSTEM |
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Microsoft Quality Windows Audio Video Experience (qWave) Support Driver |
| FileVersion (#2) | 10.0.26100.7705 (WinBuild.160101.0800) |
| InternalName | qwavedrv.sys |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | qwavedrv.sys |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion (#2) | 10.0.26100.7705 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2035-Aug-11 15:16:50 |
| Version | 0.0 |
| SizeofData | 37 |
| AddressOfRawData | 0xb700 |
| PointerToRawData | 0xb700 |
| Referenced File | qwavedrv.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2035-Aug-11 15:16:50 |
| Version | 0.0 |
| SizeofData | 544 |
| AddressOfRawData | 0xb728 |
| PointerToRawData | 0xb728 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2035-Aug-11 15:16:50 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0xb9c8 |
| PointerToRawData | 0xb9c8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2035-Aug-11 15:16:50 |
| Version | 0.0 |
| SizeofData | 4 |
| AddressOfRawData | 0xb9ec |
| PointerToRawData | 0xb9ec |
| Size | 0x148 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14000d080 |
| GuardCFCheckFunctionPointer | 5368771536 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0x357fabe4 |
|---|---|
| Unmarked objects | 0 |
| Total imports | 80 |
| Imports (33145) | 3 |
| Unmarked objects (#2) | 3 |
| C objects (33145) | 10 |
| ASM objects (33145) | 9 |
| C objects (LTCG) (33145) | 12 |
| Resource objects (33145) | 1 |
| Linker (33145) | 1 |
No comments yet.