Gridinsoft Logo

The WdBoot.sys (Microsoft antimalware boot driver) File Analysis

Technical Analysis

File Name WdBoot.sys
File Type
PE32+ executable (native) x86-64, for MS Windows
Scanner Version 1.0.168.174
Database Version 2024-03-11 18:00:41 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
46,688
File Size (bytes)
2024-03-11
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
5925250bddb94b0a5fa0e7feed36c520
SHA1
e9946c463109418520f608edd3a681b23ae0f626
SHA256
0845344f7bfaa94af90920a5346078e6261eea3a1a77795dda5b70b38609348b
SHA512
df1a20e3beb84fcf74df44f5e3b473f7b00a8722d7e7221943fb656d2525c3bd28ff200afa46fa995847899213d4cc6ef2f1bf25787b14eaf57de40ca1187be7
ImpHash
849a6f20e1993d772db6ae7a9c61349e

PE Analysis

Basic Information

Image Base 0x1c0000000
Entry Point 0x1c000c350
Compilation Time 2036-11-17 22:08:26
Checksum 0x00010490 (Actual: 0x00010fbc)
OS Version 10.0
PEiD Signatures PE32+ executable (native) x86-64, for MS Windows
PDB Path WdBoot.pdb
Digital Signature OK
Imports 2 libraries
ntoskrnl, cng
Exports 0 functions
Resources 2 Resources
Sections 10 Sections

Version Information

CompanyName Microsoft Corporation
FileDescription Microsoft antimalware boot driver
FileVersion 4.18.1909.6 (WinBuild.160101.0800)
InternalName WdBoot
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename WdBoot.sys
ProductName Microsoft® Windows® Operating System
ProductVersion 4.18.1909.6
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 7,017 bytes 7,168 bytes 6.38 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ CCCA7ECD998ADBE334E1247049586772
.rdata 0x00003000 4,004 bytes 4,096 bytes 4.93 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ 05F75A663548D055D9698D2E809CE611
.data 0x00004000 416 bytes 512 bytes 0.44 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE E9889F620BE2BFF4CB3D1485149B0313
.pdata 0x00005000 840 bytes 1,024 bytes 3.67 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ 41B41E06F5B6860F09D24AA9730266BA
.idata 0x00006000 1,736 bytes 2,048 bytes 3.89 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ AE99DF3FCC27AA8C4547030234B0EA55
PAGE 0x00007000 12,419 bytes 12,800 bytes 6.22 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 2E087E75E0AD4C697A353823B27FAE08
INIT 0x0000b000 5,033 bytes 5,120 bytes 6.16 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 86C6E76AAC212A12B9992F62E2C2BD64
GFIDS 0x0000d000 32 bytes 512 bytes 0.32 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ BE87F1DFF081E13E55979A0A8819BE6B
.rsrc 0x0000e000 2,536 bytes 2,560 bytes 3.48 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ B15BD7CCF9FA061F5EB819A7E8BF7160
.reloc 0x0000f000 784 bytes 1,024 bytes 4.07 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ A507A79291B9AD7B485748630E9C71BD

Resource Analysis

Total Resources: 2 (2,274 bytes)
Resource Type Count Total Size Percentage
MSELAMCERTINFOID 1 1,358 bytes
59.7%
RT_VERSION 1 916 bytes
40.3%

Certificate Chain Analysis

Certificate Information
Product Microsoft® Windows® Operating System
Description Microsoft antimalware boot driver
File Version 4.18.1909.6 (WinBuild.160101.0800)
Original Name WdBoot.sys
Signing Date 02:04 AM 09/25/2019 (2121 days ago)
Verification Status Signed
Signers Microsoft Windows Early Launch Anti-malware Publisher; Microsoft Code Signing PCA 2010; Microsoft Root Certificate Authority 2010
Counter Signers Microsoft Time-Stamp Service; Microsoft Time-Stamp PCA 2010; Microsoft Root Certificate Authority 2010
Internal Name WdBoot
Copyright © Microsoft Corporation. All rights reserved.
Certificate Chain Summary
Microsoft Windows Early Launch Anti-malware Publisher #1 Primary
Validity Period: 2019-03-27 19:20:04 → 2020-03-27 19:20:04
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 02 B3 AC DF 0C 8A 8E B8 FC 9B 00 00 00 00 02 B3
Microsoft Code Signing PCA 2010 #2 Chain
Validity Period: 2010-07-06 20:40:17 → 2025-07-06 20:50:17
Signature Algorithm: sha256RSA
Serial Number: 61 0C 52 4C 00 00 00 00 00 03
Microsoft Time-Stamp PCA 2010 #3 Chain
Validity Period: 2010-07-01 21:36:55 → 2025-07-01 21:46:55
Signature Algorithm: sha256RSA
Serial Number: 61 09 81 2A 00 00 00 00 00 02
Microsoft Time-Stamp Service #4 Chain
Validity Period: 2019-09-06 20:41:07 → 2020-12-04 20:41:07
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 00 FD 44 2C A0 F1 35 72 04 A9 00 00 00 00 00 FD

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware