MultiKey.sys

Virtual USB MultiKey x86

Multikey

The file MultiKey.sys has been detected as malware by 26 anti-virus scanners. It runs as a Windows kernel mode device driver named “Virtual USB MultiKey”.
Publisher:
Chingachguk & Denger2k (Elite & SP edition)  (signed by Multikey)

Product:
Virtual USB MultiKey x86

Version:
0.18.2.4 built by: WinDDK

MD5:
df497d76edb931298cf195e7288f7bff

SHA-1:
99dbf6f05db46824b13a8869973a55378ac2d7ca

SHA-256:
c8e59dfac888bf2f825a398d7232aca21658c8545d5ba89144ea7af56192383f

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
4/25/2024 11:24:07 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.6755628
980

AegisLab AV Signature
Troj.Dropper.W32.Agent
2.1.4+

Agnitum Outpost
Trojan.Packed
7.1.1

AVG
Generic5_c
2015.0.3458

Baidu Antivirus
Trojan.Win32.VMProtect
4.0.3.14531

Bitdefender
Trojan.Generic.6755628
1.0.20.755

Bkav FE
W32.Clod6aa.Trojan
1.3.0.4959

Clam AntiVirus
Win.Trojan.Agent-17009
0.98/213

Emsisoft Anti-Malware
Trojan.Generic.6755628
8.14.05.31.10

ESET NOD32
Win32/Packed.VMProtect.AAA (variant)
8.9860

F-Secure
Trojan.Generic.6755628
11.2014-31-05_7

G Data
Trojan.Generic.6755628
14.5.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.178.12229

McAfee
Artemis!DF497D76EDB9
5600.7114

Microsoft Security Essentials
VirTool:Win32/Obfuscator.XZ
1.10600

MicroWorld eScan
Trojan.Generic.6755628
15.0.0.453

NANO AntiVirus
Trojan.Win32.Agent2.baqcpo
0.28.0.59921

Norman
Suspicious_Gen2.UCQPR
11.20140531

nProtect
Trojan.Generic.6755628
14.05.28.01

Panda Antivirus
Trj/Thed.W
14.05.31.10

Rising Antivirus
PE:Trojan.Win32.Generic.1335DF0F!322297615
23.00.65.14529

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_SPNR.0BJ313
7.2.151

Trend Micro
TROJ_SPNR.0BJ313
10.465.31

VIPRE Antivirus
Trojan.Win32.Generic
29702

File size:
205 KB (209,928 bytes)

Product version:
0.18.2.4

Copyright:
Copyright (C) 2004-2009 by Chingachguk & Denger2k

Original file name:
MultiKey.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\multikey.sys

Digital Signature
Signed by:

Authority:
Multikey

Valid from:
4/20/2010 1:17:23 PM

Valid to:
1/1/2040 1:59:59 AM

Subject:
CN=Multikey

Issuer:
CN=Multikey

Serial number:
7A19072DF64273A141B5661F27ABE341

File PE Metadata
Compilation timestamp:
4/20/2010 12:42:27 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
3072:vyMsTtacw33KVC/NOR/o++7UCmNzovW1W0nMyw4ZqX3sXGf4f3SVjNVYV:vyMspAnsR//+7UCU1frrqX3sXBCVcV

Entry address:
0xD2E8

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 0E, FF, FF, FF, 44, D3, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B6, D7, 00, 00, 10, 06, 00, 00, 34, D3, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, D8, 00, 00, 00, 06, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, DA, D7, 00, 00, C4, D7, 00, 00, F0, D7, 00, 00, 00, 00, 00, 00, 42, D4, 00, 00, 5A, D4, 00, 00, 68, D4, 00, 00, 80, D4, 00, 00, 96, D4, 00, 00, B4, D4, 00, 00, CC, D4, 00, 00, E4, D4, 00, 00, F8, D4, 00, 00...
 
[+]

Code size:
200.5 KB (205,312 bytes)

Driver
Display name:
Virtual USB MultiKey

Service name:
multikey

Type:
Kernel device driver (KernelDriver)

Group:
Extended Base


Remove MultiKey.sys - Powered by Reason Core Security