Gridinsoft Logo

The WinDivert64.sys (The WinDivert 2.2 driver [URL: https://reqrypt.org/windivert.html] [Bitcoin: 1C5vZVSbizPeZ8ydTYhUfm4LA2cNwBfcYh]) File Analysis

Technical Analysis

File Name WinDivert64.sys
File Type
PE32+ executable (native) x86-64, for MS Windows
Scanner Version 1.0.212.174
Database Version 2025-04-01 16:00:30 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
94,144
File Size (bytes)
2025-04-01
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
89ed5be7ea83c01d0de33d3519944aa5
SHA1
4c9b9c74529399abacc2284de1dead5f2332ee9b
SHA256
8da085332782708d8767bcace5327a6ec7283c17cfb85e40b03cd2323a90ddc2
SHA512
be6530fa0e26441441028b530cd6fc4f900448916e137f92613a1f886c16399d415ddd17f7f8847258cc19c63b1510f2f3068942203c50486e48eed838f9f138
ImpHash
5bfe3723089cbcfcc271ba6d7ab617aa

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x140001184
Compilation Time 2022-09-20 01:09:22
Checksum 0x0001d693 (Actual: 0x0001d693)
OS Version 10.0
PEiD Signatures PE32+ executable (native) x86-64, for MS Windows
PDB Path C:\WinDivert-2.2.2\install\MSVC\amd64\WinDivert64.pdb
Digital Signature OK
Imports 5 libraries
ntoskrnl, HAL, NDIS, fwpkclnt, WDFLDR
Exports 0 functions
Resources 2 Resources
Sections 8 Sections

Version Information

CompanyName Basil
FileDescription The WinDivert 2.2 driver [URL: https://reqrypt.org/windivert.html] [Bitcoin: 1C5vZVSbizPeZ8ydTYhUfm4LA2cNwBfcYh]
FileVersion 2.2
InternalName WinDivert.sys
LegalCopyright Copyright © Basil 2011-2022
OriginalFilename WinDivert.sys
ProductName WinDivert 2.2 driver
ProductVersion 2.2
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 45,818 bytes 46,080 bytes 6.28 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ DB6635B6C8D9CABCB4F8971F3275681D
.rdata 0x0000d000 17,912 bytes 17,920 bytes 4.32 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ 2030F4EBE47BDBC617B21DBD3CCDE1DB
.data 0x00012000 16,440 bytes 512 bytes 1.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE E5C85A8D3D94108BE67648DBC5457C3C
.pdata 0x00017000 1,716 bytes 2,048 bytes 4.16 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ 6D495F657E7F3C759E3BAEDCC01FB830
.gfids 0x00018000 4 bytes 512 bytes 0.02 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ 1CF2856B26691BE80E10679AEE1138E4
INIT 0x00019000 2,202 bytes 2,560 bytes 4.76 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 77C60077276747C88537E52D05E52163
.rsrc 0x0001a000 1,144 bytes 1,536 bytes 2.71 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 75551BAAABDE98CE95255E6B418893F1
.reloc 0x0001b000 420 bytes 512 bytes 4.63 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 66FB9B26EE5CD3F39396321B34E09CDD

Resource Analysis

Total Resources: 2 (980 bytes)
Resource Type Count Total Size Percentage
RT_MESSAGETABLE 1 68 bytes
6.9%
RT_VERSION 1 912 bytes
93.1%

Certificate Chain Analysis

Certificate Information
Product WinDivert 2.2 driver
Description The WinDivert 2.2 driver [URL: https://reqrypt.org/windivert.html] [Bitcoin: 1C5vZVSbizPeZ8ydTYhUfm4LA2cNwBfcYh]
File Version 2.2
Original Name WinDivert.sys
Signing Date 04:54 AM 09/20/2022 (989 days ago)
Verification Status Signed
Signers 成都密思听科技有限公司; Sectigo Public Code Signing CA EV R36; Sectigo Public Code Signing Root R46; Sectigo (AAA)
Counter Signers Sectigo RSA Time Stamping Signer #3; Sectigo RSA Time Stamping CA; Sectigo
Internal Name WinDivert.sys
Copyright Copyright © Basil 2011-2022
Certificate Chain Summary
AAA Certificate Services #1 Primary
Validity Period: 2004-01-01 00:00:00 → 2028-12-31 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 01
Sectigo Public Code Signing Root R46 #2 Chain
Validity Period: 2021-05-25 00:00:00 → 2028-12-31 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 48 FC 93 B4 60 55 94 8D 36 A7 C9 8A 89 D6 94 16
Sectigo Public Code Signing CA EV R36 #3 Chain
Validity Period: 2021-03-22 00:00:00 → 2036-03-21 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 33 D7 08 A8 91 40 53 19 E2 A5 BB D3 39 B9 AD 6E
Sectigo RSA Time Stamping CA #4 Chain
Validity Period: 2019-05-02 00:00:00 → 2038-01-18 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 30 0F 6F AC DD 66 98 74 7C A9 46 36 A7 78 2D B9
Sectigo RSA Time Stamping Signer #3 #5 Chain
Validity Period: 2022-05-11 00:00:00 → 2033-08-10 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 90 39 7F 9A D2 4A 3A 13 F2 BD 91 5F 08 38 A9 43
成都密思听科技有限公司 #6 Chain
Validity Period: 2022-05-25 00:00:00 → 2023-05-25 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 61 50 19 91 B1 8F 32 38 04 52 51 37 DC 25 00 5A
Microsoft Windows Hardware Compatibility Publisher #7 Chain
Validity Period: 2022-06-07 18:08:06 → 2023-06-01 18:08:06
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 00 57 EE 4D 65 9A 92 3E 7C 10 00 00 00 00 00 57
Microsoft Windows Third Party Component CA 2014 #8 Chain
Validity Period: 2014-10-15 20:31:27 → 2029-10-15 20:41:27
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 00 0D 69 0D 5D 78 93 D0 76 DF 00 00 00 00 00 0D
Microsoft Time-Stamp Service #9 Chain
Validity Period: 2022-03-02 18:51:22 → 2023-05-11 18:51:22
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 01 A7 35 BB 2E C2 64 85 50 29 00 01 00 00 01 A7
Microsoft Time-Stamp PCA 2010 #10 Chain
Validity Period: 2021-09-30 18:22:25 → 2030-09-30 18:32:25
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 15

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware