ctmov.sys

CypherTec Inc.

It runs as a Windows kernel mode device driver named “CTMOV2”.
Publisher:
CypherTec Inc.  (signed and verified)

Version:
1.3.2.0

MD5:
11b871c10318ca39e629ec276a2115ee

SHA-1:
7094cf0fda8f2bcbece7f0e6168208a771eb1d7d

SHA-256:
a152186683db2958938ce83b2576294b3f4bc635ca0a8506651f96659e69f9fc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 9:58:25 AM UTC  (today)

File size:
104.1 KB (106,592 bytes)

Product version:
1.3.2.0

Copyright:
Copyright (C) 2003-2009 CypherTec Inc., All Rights Reserved.

Original file name:
cymon.sys

File type:
Driver (Win32 SYS)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/10/2009 9:00:00 AM

Valid to:
6/11/2010 8:59:59 AM

Subject:
CN=CypherTec Inc., OU=Business Development, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=CypherTec Inc., L=Shinjuku-ku, S=Tokyo, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0966DEEACB47388A7AF631EB5AF5ADB2

File PE Metadata
Compilation timestamp:
7/21/2009 10:18:50 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.10

CTPH (ssdeep):
3072:xHZ4BArhaLtwv3eODxIqMqqDL2/CdKQMW:xHlh8wvuOSqqDL6CRMW

Entry address:
0x632

Entry point:
6A, 30, 68, 30, FA, 01, 00, E8, 0E, F2, 00, 00, 33, F6, 89, 75, E4, 89, 75, DC, 89, 75, FC, 33, DB, 43, 89, 5D, FC, 56, 68, F0, 64, 02, 00, 56, 56, E8, B2, F1, 00, 00, 6A, 76, 59, 33, C0, BF, 00, 63, 02, 00, F3, AB, 68, 1C, 6D, 02, 00, 8B, 3D, 2C, F9, 01, 00, FF, D7, 68, 04, 69, 02, 00, FF, D7, 89, 75, E0, 81, 7D, E0, FF, 00, 00, 00, 7D, 0F, 8B, 45, E0, 89, 34, 85, 20, 69, 02, 00, FF, 45, E0, EB, E8, C7, 05, 00, 63, 02, 00, 10, CE, CE, CE, C7, 05, 04, 63, 02, 00, D8, 01, 00, 00, 68, 08, 63, 02, 00, FF, 15...
 
[+]

Entropy:
6.5561

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
62.9 KB (64,384 bytes)

Driver
Display name:
CTMOV2

Type:
Kernel device driver (KernelDriver)


Scan ctmov.sys - Powered by Reason Core Security