buttonconverter.sys - Clean (13/100) - DriverShield Analysis

Analysis of buttonconverter.sys: clean verdict, risk score 13/100. 0 YARA matches. SHA256 16a900fbab30d008. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.

buttonconverter.sys - Analysis Report

DriverShield analyzed the Windows kernel driver buttonconverter.sys and assigned a verdict of Clean with a composite risk score of 13/100, indicating no notable risk signals (0-29 band).

VerdictClean (13/100)
YARA matches0
File size44032 bytes
Analyzed2026-03-22
SHA25616a900fbab30d008f01f4cae96347bf313d9d13c7fe430249a0bf4322534cb18
SHA1e88cccc8875be04df684fdac2532f92f5fbc1f5d
MD5ef2a1f3c5ec4efffbe9a69b892fba29c

Driver identity

Version resource data embedded in the buttonconverter.sys PE header, as extracted by the analysis engine.

File descriptionButton Converter Driver
ProductMicrosoft® Windows® Operating System
CompanyMicrosoft Corporation
Original filenamebtnconv.sys
Internal namebtnconv.sys
File version10.0.19041.1 (WinBuild.160101.0800)
Copyright© Microsoft Corporation. All rights reserved.

How the 13/100 score breaks down

Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.

ComponentSub-score
Multi-engine consensus0 / 100
YARA signature matches0 / 100
Dangerous kernel imports30 / 100
IOCTL dispatch surface42 / 100
Known-vulnerable corpus0 / 100
Code-signing state50 / 100
Packing and entropy0 / 100
Dynamic behaviour0 / 100
CVE cross-reference0 / 100

Kernel imports (5)

Kernel-mode APIs resolved from the Import Address Table of buttonconverter.sys, ranked by exploitation relevance.

APIRiskWhy it matters
MmGetSystemRoutineAddresshighPotentially dangerous - could be used for privilege escalation or security bypass
KeBugCheckExmediumModerate risk - system modification capability
DbgPrintExlowStandard kernel API - generally benign
ExAllocatePoolWithTaglowStandard kernel API - generally benign
RtlInitUnicodeStringlowStandard kernel API - generally benign

IOCTL dispatch codes (14)

Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.

CodeSeverityTransferDescription
0x002200F0mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #60
0x0080530DmediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #1219
0x00223BE8mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #3834
0x0080C715mediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #453
0x00341FE8mediumMETHOD_BUFFEREDFILE_DEVICE_DISK Function #2042
0x0080B389mediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #3298
0x0034DF35mediumMETHOD_IN_DIRECTFILE_DEVICE_DISK Function #1997
0x00345F3DmediumMETHOD_IN_DIRECTFILE_DEVICE_DISK Function #1999
0x0034470DmediumMETHOD_IN_DIRECTFILE_DEVICE_DISK Function #451
0x00343420mediumMETHOD_BUFFEREDFILE_DEVICE_DISK Function #3336
0x0022341CmediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #3335
0x00800100mediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #64
0x00220100mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #64
0x0034038CmediumMETHOD_BUFFEREDFILE_DEVICE_DISK Function #227

PE sections

Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.

SectionVirtual sizeRaw sizeEntropyFlags
.text0x5BE90x5C006.1CODE, EXEC, READ
.rdata0x11A00x12005.33IDATA, READ
.data0x05700x04002.04IDATA, READ, WRITE
.pdata0x03840x04003.9IDATA, READ
.idata0x06400x08003.57IDATA, READ
PAGE0x19730x1A005.97CODE, EXEC, READ
INIT0x04EA0x06005.31CODE, EXEC, READ, DISCARD
GFIDS0x004C0x02000.71IDATA, READ, DISCARD
.rsrc0x04000x04003.3IDATA, READ, DISCARD
.reloc0x03D40x04005.73IDATA, READ, DISCARD

Exploit mitigations

Control Flow GuardEnabled
ASLREnabled
DEPEnabled
Integrity checkNot enforced
Mitigation score80 / 100

MITRE ATT&CK techniques (7)

Techniques this driver could enable if loaded by an adversary.

IDTechniqueTactic
T1112Modify RegistryDefense Evasion
T1211Exploitation for Defense EvasionDefense Evasion
T1543.003Windows ServicePersistence
T1547.001Registry Run KeysPersistence
T1553.002Subvert Trust Controls: Code SigningDefense Evasion
T1553.006Code Signing Policy ModificationDefense Evasion
T1652Device Driver DiscoveryDiscovery

Symbolic execution

Engine angr, status no_findings, 0 paths explored at a maximum depth of 0. Vulnerability classes reached: 0. Exploitable paths: 0.

Frequently asked questions about buttonconverter.sys

Is buttonconverter.sys safe?

Based on DriverShield static and dynamic analysis, buttonconverter.sys is assessed as clean, with no notable risk signals. Its composite risk score is 13/100 (verdict: clean). Always validate findings independently before acting.

What is the risk score of buttonconverter.sys?

buttonconverter.sys has a DriverShield composite risk score of 13/100, placing it in the clean verdict band. SHA256: 16a900fbab30d008f01f4cae96347bf313d9d13c7fe430249a0bf4322534cb18.

What is buttonconverter.sys?

buttonconverter.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators.

Related: What an IOCTL dispatch code is · BYOVD research index · full driver database · CVE library · code signing atlas


DriverShield © 2025-2026 · Terms · Privacy · Contact