PECKP.sys

POWERENTER

Client Server International. Inc. Beijing Branch

It runs as a Windows 64-bit kernel mode device driver named “PECKbdProtector”.
Publisher:
CSII  (signed by Client Server International. Inc. Beijing Branch)

Product:
POWERENTER

Description:
PowerEnter Keyboard Protector

Version:
1, 3, 1, 75

MD5:
486524c1d1a52128721479291b4a4dd3

SHA-1:
237448fd19d25fee525d4048ad15bae4bd64ecff

SHA-256:
150598a5a7def3ae66732e1df1dd009e93f1525910df6ecf1a1362cf245eb5cf

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 11:19:56 AM UTC  (today)

File size:
237.1 KB (242,840 bytes)

Product version:
1, 3, 1, 75

Copyright:
Copyright (C) 2010-2011 CSII

Trademarks:
POWERENTER

Original file name:
PECKP.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\peckp.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/22/2010 8:00:00 AM

Valid to:
4/22/2012 7:59:59 AM

Subject:
CN=Client Server International. Inc. Beijing Branch, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Client Server International. Inc. Beijing Branch, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
48A08CB3544EC389CC26F4EF590F8B10

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
6144:IJjr8BEHBQ2pqyI9cE/9dDTJjvqVAjurH6xEZN:IJ/3QNh9cE7pjASeaGN

Entry point:
60, E8, BA, 0F, 00, 00, 9C, 83, FB, 03, E8, C1, DD, FF, FF, E8, A8, EF, FF, FF, E8, 2C, 0A, 00, 00, 9C, C6, 04, 24, F0, E8, 71, 21, FD, FF, 21, 5A, 64, 8E, 3A, 03, 4D, 39, C2, 0E, 39, C4, 69, 73, F0, 47, E1, 0A, 7A, 0B, B6, 21, 1D, 05, 10, 86, 11, ED, 61, A8, A1, 30, 68, 90, 7A, 63, AA, 34, AF, 1F, 1C, C0, 71, 59, 94, 25, B9, 9E, 5C, B0, A7, 7F, BC, 3E, 7A, 15, 49, 74, 9B, 02, 8A, F2, DA, 64, AD, D4, DE, 79, 19, 36, 7B, BE, 52, 11, BC, 02, 3E, 2E, 31, 31, 92, 0B, 9D, 89, 92, DC, 48, B3, 3E, 65, 46, F1, 6D...
 
[+]

Entropy:
7.6751

Packer / compiler:
ASPack v1.08.04

Driver
Display name:
PECKbdProtector

Type:
Kernel device driver (KernelDriver)


Scan PECKP.sys - Powered by Reason Core Security