pikbd.sys

Pluralinput Keyboard Driver

Christian Gulden

It runs as a Windows kernel mode device driver named “Pluralinput Keyboard 0.8.4”.
Publisher:
Christian Gulden  (signed and verified)

Product:
Pluralinput Keyboard Driver

Version:
1.20.284.0

MD5:
535ff7f78c0228c28148fd4eac6232a2

SHA-1:
46ec82d6e1d3101d122f4f395d42d2286d68326b

SHA-256:
085436745db3108815fd322b5203aa3ff2e9c1a0c274f95fde3e9314a5312378

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
10/20/2018 1:39:37 AM UTC  (today)

File size:
20.9 KB (21,432 bytes)

Product version:
1.20

Copyright:
© Christian Gulden 2013

Original file name:
pikbd.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\pikbd.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/28/2012 3:42:30 PM

Valid to:
11/17/2013 1:44:03 PM

Subject:
CN=Christian Gulden, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11210A81441DD55BE2AF97ECDF3804633A8A

File PE Metadata
Compilation timestamp:
9/10/2013 5:11:02 PM

OS version:
6.2

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
11.0

CTPH (ssdeep):
384:WMsmBUYezZyoXPCBM0b+7RTw/i9BZTUlsdCPIKluYpbwnYI4wb:WMsB9/CK0biw/i54qCQIuSbzO

Entry address:
0x276C

Entry point:
8B, FF, 55, 8B, EC, E8, D6, 38, 00, 00, 5D, E9, 1C, FF, FF, FF, CC, CC, CC, CC, CC, CC, E8, 31, 00, 00, 00, C2, 08, 00, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, A1, 74, 47, 40, 00, 85, C0, 74, 0C, 3D, 90, 27, 40, 00, 74, 05, FF, 75, 08, FF, D0, E8, 09, 00, 00, 00, 5D, C2, 04, 00, CC, CC, CC, CC, CC, 8B, FF, 56, BE, 54, 40, 40, 00, 56, E8, 6C, 00, 00, 00, FF, 35, 78, 47, 40, 00, 56, 68, 90, 49, 40, 00, E8, 23, 01, 00, 00, 5E, C3, CC, CC, CC, CC, CC, 8B, FF, 57, B8, 88, 40, 40, 00, BF, 90, 40, 40, 00, 3B...
 
[+]

Entropy:
6.3252

Code size:
9 KB (9,216 bytes)

Driver
Display name:
Pluralinput Keyboard 0.8.4

Service name:
pikbd

Type:
Kernel device driver (KernelDriver)

Group:
Keyboard Port


Scan pikbd.sys - Powered by Reason Core Security