SndVol.exe

  • File Path: C:\WINDOWS\system32\SndVol.exe
  • Description: Volume Mixer

Screenshot

SndVol.exe

Hashes

Type Hash
MD5 BE6B28D62DB5B2AAF92B00DBD717D453
SHA1 C3868D5F073434C27E1FEC3DC681C2EC1A3B266C
SHA256 3689A43858DB4845B5DA04EC5140E0616118D56A99F0C498ED5A90C4E9998CAB
SHA384 578918C5A3F207449A7237A1BA902EBAE0C57DCDC2495D8D81FFFA4EAE0381F1CABA2E3B8EF4E20D4BDF2AE997F94FF3
SHA512 777900BC98D6542B6142D9B8F28B129AFF36DC9A6E417BC508696042E2615A8594D5139D33987B5F537CBAC0FBD22E143E7FED05CF99B4B35B7EE9E53F144016
SSDEEP 3072:tEKC5GybtCSb6K4c8TklfXzHgasD8sazJeYEoqGcQDWkyzjbEyB7HbIrnvkSW:tEKCjCS2KR8ULgasD8se3cEbvy10rTW

Signature

  • Status: Signature verified.
  • Serial: 330000023241FB59996DCC4DFF000000000232
  • Thumbprint: FF82BC38E1DA5E596DF374C53E3617F7EDA36B06
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: SndVol.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.18362.1 (WinBuild.160101.0800)
  • Product Version: 10.0.18362.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

File Similarity (ssdeep match)

File Score
C:\Windows\system32\SndVol.exe 30
C:\windows\system32\SndVol.exe 32
C:\WINDOWS\SysWOW64\SndVol.exe 27
C:\Windows\SysWOW64\SndVol.exe 30
C:\Windows\SysWOW64\SndVol.exe 33
C:\WINDOWS\SysWOW64\SndVol.exe 35
C:\Windows\SysWOW64\SndVol.exe 30
C:\windows\SysWOW64\SndVol.exe 32
C:\Windows\SysWOW64\SndVol.exe 29

Possible Misuse

The following table contains possible examples of SndVol.exe being misused. While SndVol.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
signature-base thor_inverse_matches.yar description = “Anomaly rule looking for certain strings in a system file (maybe false positive on certain systems) - file SndVol.exe” CC BY-NC 4.0
signature-base thor_inverse_matches.yar filename == “sndvol.exe” CC BY-NC 4.0

MIT License. Copyright (c) 2020-2021 Strontic.