keyscrambler.sys

KeyScrambler

QFX Software Corporation

It runs as a Windows kernel mode device driver named “KeyScrambler”.
Publisher:
QFX Software Corporation  (signed and verified)

Product:
KeyScrambler (R)

Description:
KeyScrambler Keyboard Encryption Driver

Version:
 built by: WinDDK

MD5:
b143d56ace006580d8c38733cec17de7

SHA-1:
be16caa19f0e4f80fb05fd3cfcf649b457e00a5d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 12:34:06 AM UTC  (today)

File size:
110.5 KB (113,128 bytes)

Product version:


Copyright:
(c) QFX Software Corporation. All rights reserved

Original file name:
keyscrambler.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\keyscrambler.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/2/2007 5:57:58 AM

Valid to:
3/2/2008 5:57:58 AM

Subject:
E=qfxsoft@qfxsoftware.com, CN=QFX Software Corporation, O=QFX Software Corporation, C=US

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000011112F1598E

File PE Metadata
Compilation timestamp:
3/12/2007 7:57:37 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
1536:UyfenXxf2bMsLAD4HB7gGkr1mKGq4a3y5ikucpmGLaTxGrYoq/5ps0p91QfWiv:/GnXxf21U8h7gp73JTCYnsKS

Entry address:
0x1888E

Entry point:
8B, FF, 55, 8B, EC, A1, 84, 56, 02, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1E, 8B, 15, 50, 0F, 02, 00, B8, 84, 56, 02, 00, C1, E8, 08, 33, 02, A3, 84, 56, 02, 00, 75, 07, 8B, C1, A3, 84, 56, 02, 00, F7, D0, A3, 88, 56, 02, 00, 5D, E9, 36, FF, FF, FF, F8, 88, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 98, 8B, 01, 00, 00, 0F, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, E0, 89, 01, 00, F4, 89, 01, 00, 06, 8A, 01, 00, 24, 8A, 01, 00, 36, 8A, 01, 00, 46, 8A...
 
[+]

Entropy:
6.6906

Code size:
74.8 KB (76,544 bytes)

Driver
Display name:
KeyScrambler

Type:
Kernel device driver (KernelDriver)


Scan keyscrambler.sys - Powered by Reason Core Security