elytsxu.sys

UxStyle Community Edition

The Within Network, LLC

It runs as a Windows 64-bit kernel mode device driver named “uxstyle”.
Publisher:
The Within Network, LLC  (signed and verified)

Product:
UxStyle Community Edition

Description:
UxStyle Community Edition Kernel Driver

Version:
0.2.4.1

MD5:
d063866ec39e92fe5fdc18582adbdb0c

SHA-1:
b53ed18ec84a8989799714d5b2fd87e864961948

SHA-256:
6fd881cdd7a202ab94423fadc9ca3a7ff711b1595b4340d416179ed811d9a6d0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 8:51:50 AM UTC  (today)

File size:
31.7 KB (32,424 bytes)

Product version:
0.2.4.1

Copyright:
Copyrighted content

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\elytsxu.sys

Digital Signature
Authority:
GlobalSign nv-sa

Subject:
CN="The Within Network, LLC", O="The Within Network, LLC", L=Purcellville, S=Virginia, C=US

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E2B698769FBA3F4FF90834BEF0F2A664

File PE Metadata
Compilation timestamp:
1/27/2015 9:15:14 PM

OS version:
6.3

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
12.0

CTPH (ssdeep):
384:pGygdqfJVTFHY8wWelc6CisL0o4cTFroWGswH5YBmzuEnz+vqCdrWMQM8wD6INAG:pTxM8B4o4cT9oWGswZnzuIcq+L8M6i

Entry address:
0x2944

Entry point:
48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8B, DA, 48, 8B, F9, E8, A7, 56, 00, 00, 48, 8B, D3, 48, 8B, CF, 48, 8B, 5C, 24, 30, 48, 83, C4, 20, 5F, E9, F2, EC, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 3B, 0D, 89, 16, 00, 00, 75, 10, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 01, C3, 48, C1, C9, 10, E9, 02, 00, 00, 00, CC, CC, B9, 02, 00, 00, 00, CD, 29, CC, FF, 25, 9A, 06, 00, 00, FF, 25, 54, 07, 00, 00, FF, 25, AE, 07, 00, 00, FF, 25, E8, 07, 00, 00, FF, 25, EA, 07...
 
[+]

Code size:
16.5 KB (16,896 bytes)

Driver
Display name:
uxstyle

Type:
Kernel device driver (KernelDriver)

Group:
File System


Scan elytsxu.sys - Powered by Reason Core Security