Information about athrx.sys

athrx.sys

athrx.sys is a Windows file recorded in the ThreatInfo database. It is associated with Driver for Qualcomm Atheros CB42/CB43/MB42/MB43 Network Adapter. The reported company name is Qualcomm Atheros Communications, Inc.. The current detection status is Undefined, based on the latest analysis from 2023-06-25 23:56:51 (2 years ago).

ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.

Product Name: Driver for Qualcomm Atheros CB42/CB43/MB42/MB43 Network Adapter
Company Name: Qualcomm Atheros Communications, Inc.
MD5: c77af78cae5e3684bd6b8960b025bb1c
Size: 3 MB
First Published: 2018-07-24 11:20:14 (7 years ago)
Latest Published: 2023-06-25 23:56:51 (2 years ago)
Status: Undefined (on last analysis)
Analysis Date: 2023-06-25 23:56:51 (2 years ago)
Signed By: Qualcomm Atheros
Status: Trusted Publisher

ThreatInfo marks this publisher as trusted for this record, but the file hash and source should still match the expected software distribution.

%programfiles%\drivertoolkit\download\bb312bfd258b7466865a6315461702e4\drivers\production\windows7-x64
%programfiles%\drivertoolkit\download\bb312bfd258b7466865a6315461702e4\drivers\production\windows7-x64
%localappdata%\slimware utilities inc\slimdrivers\backups\20171210t152840284340\pci

ThreatInfo has observed athrx.sys in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

28.6%
14.3%
14.3%
14.3%
14.3%
14.3%

The strongest geographic signal for this file is Italy with 28.6% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 57.1%
Windows 7 42.9%

The most common operating system signal for athrx.sys is Windows 10 with 57.1% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

athrx.sys is identified as pe for 64 systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Native
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000000010000
Entry Address: 0x00421064

PE Sections:

Name Size of data MD5
.text 3177472 bdf77a6352cac2379693dad3d7da314d
.rdata 785408 21242dd4cde572d266dc2b1040306709
.data 104448 380c3370bec72d5e584519347f03f346
.pdata 77312 e0f68d30a8ee8ffb10a4440ad242adec
INIT 4608 bf78689622ba8256baee030cd165fe62
.rsrc 1536 ae9bb880bfcd214734dfc0a302b38fad
.reloc 17408 1c325270ff6bb47fe19ff7bb406f2d13

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: