EyeSign.sys

EyeSign.sys

IrisGuard UK Ltd

It runs as a Windows kernel mode device driver named “EyeSign”.
Publisher:
IrisGuard Inc.  (signed by IrisGuard UK Ltd)

Product:
EyeSign.sys

Description:
IrisGuard EyeSign Driver

Version:
10.2.0.0 built by: WinDDK

MD5:
f671dbcea5ef6b30072b10968fb8d117

SHA-1:
28ae0bdf0ab7ef2532b9a904b782667d9b5b2ffe

SHA-256:
e2f191150ed6fa2f9c2de27dbca15d78712910f38d949560297baf669dcd32c4

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 6:41:36 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Sality.AG
7.11.30.172

File size:
171 KB (175,104 bytes)

Product version:
10.2.0.0

Copyright:
Copyright © IrisGuard Inc. 2011/13

Original file name:
EyeSign.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\eyesign.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/19/2012 3:00:00 AM

Valid to:
7/8/2015 2:59:59 AM

Subject:
CN=IrisGuard UK Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=IrisGuard UK Ltd, L=Aylesbury, S=Bucks, C=GB

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
67097B87B05CE9C534EC63C5C42573CD

File PE Metadata
Compilation timestamp:
7/29/2013 7:14:55 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
3072:w6obpI7tIMDaxwsrOQ5qWYX2D7XVJLmI2saQTlFxa84Zq1:fmLrOQoWYGD7/LmAaQTlHO+

Entry address:
0x2773E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 02, 17, FE, FF, CC, CC, 18, 78, 02, 00, 00, 00, 00, 00, 00, 00, 00, 00, FC, 7B, 02, 00, 64, CD, 00, 00, B4, 77, 02, 00, 00, 00, 00, 00, 00, 00, 00, 00, 0A, 7C, 02, 00, 00, CD, 00, 00, D4, 77, 02, 00, 00, 00, 00, 00, 00, 00, 00, 00, AA, 7D, 02, 00, 20, CD, 00, 00, C4, 77, 02, 00, 00, 00, 00, 00, 00, 00, 00, 00, 22, 7E, 02, 00, 10, CD, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 92, 7A, 02, 00, 04, 7B, 02, 00, 7E, 7A...
 
[+]

Entropy:
6.4743

Code size:
52 KB (53,248 bytes)

Driver
Display name:
EyeSign

Type:
Kernel device driver (KernelDriver)


Scan EyeSign.sys - Powered by Reason Core Security