nocad.Sys

Watcher

QuickTerm West GmbH

It runs as a Windows kernel mode device driver named “noCAD”.
Publisher:
QuickTerm West GmbH  (signed and verified)

Product:
Watcher

Description:
QuickTerm West CAD blocker

Version:
2.00

MD5:
ebf0251b2096c38ae0df1430b24cc9f5

SHA-1:
3a360e7eab648151d2fd593877064ae9b099834e

SHA-256:
2949a94220de6af56746465b03fa97259e628a3a76810f9f1d87a463c71ba08a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 2:47:28 PM UTC  (today)

File size:
12.7 KB (12,968 bytes)

Product version:
2.00

Copyright:
Copyright (C)2004-2011

Original file name:
nocad.Sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\nocad.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/29/2010 5:31:10 PM

Valid to:
11/30/2011 5:31:06 PM

Subject:
E=d.lohr@quickterm.de, CN=QuickTerm West GmbH, O=QuickTerm West GmbH, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012C988C1D88

File PE Metadata
Compilation timestamp:
3/23/2011 1:50:47 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
384:QLwsxPHskqky0PKYLrsDmhNE54XdUb+z8:Q8KHCAKY/sXiz8

Entry address:
0x109D

Entry point:
8B, FF, 55, 8B, EC, A1, 84, 0B, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1A, A1, A4, 0A, 01, 00, 8B, 00, 35, 84, 0B, 01, 00, A3, 84, 0B, 01, 00, 75, 07, 8B, C1, A3, 84, 0B, 01, 00, F7, D0, A3, 88, 0B, 01, 00, 5D, E9, 35, FF, FF, FF, CC, CC, CC, CC, CC, 43, 74, 72, 6C, 32, 63, 61, 70, 2E, 53, 59, 53, 3A, 20, 65, 6E, 74, 65, 72, 69, 6E, 67, 20, 44, 72, 69, 76, 65, 72, 45, 6E, 74, 72, 79, 0A, 00, 2C, 11, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 08, 12, 00, 00, 80, 0A, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Code size:
3.1 KB (3,200 bytes)

Driver
Display name:
noCAD

Type:
Kernel device driver (KernelDriver)


Scan nocad.Sys - Powered by Reason Core Security