RexCrypt.sys

Secure Guard Manager

RATOC Systems, Inc.

It runs as a Windows kernel mode device driver named “SREX Secure Guard Manger Service”.
Publisher:
RATOC Systems, Inc.  (signed and verified)

Product:
Secure Guard Manager

Description:
RATOC Crypt FilterDriver

Version:
1, 0, 4, 0

MD5:
b5bc7a413bd8d55dfa506822055ae863

SHA-1:
75ad63a999c7a1fbc095fbe0a4a62caaff05a741

SHA-256:
1325e3168793419e691ee89b35313873c72f38b6da70096e762c27e02c9ad7ab

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 5:58:44 AM UTC  (today)

File size:
57.6 KB (58,960 bytes)

Product version:
2, 2, 0, 0

Copyright:
Copyright (C) RATOC Systems,Inc. 2006-2011

Original file name:
RexCrypt.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\rexcrypt.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/17/2011 9:00:00 AM

Valid to:
10/17/2012 8:59:59 AM

Subject:
CN="RATOC Systems, Inc.", OU=Development Division, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="RATOC Systems, Inc.", L=Naniwa-ku Osaka City, S=Osaka, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
34C59FCF80A3378EED17A6D05AAD5766

File PE Metadata
Compilation timestamp:
10/25/2011 4:01:26 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
1536:AGQxxuaCTymVq7wIUno8FMBg7BJDl9o9Fr:ExuaO5VqUhX7BZlkFr

Entry address:
0x33DB

Entry point:
8B, FF, 55, 8B, EC, A1, 00, 32, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1A, A1, E8, 30, 01, 00, 8B, 00, 35, 00, 32, 01, 00, A3, 00, 32, 01, 00, 75, 07, 8B, C1, A3, 00, 32, 01, 00, F7, D0, A3, 04, 32, 01, 00, 5D, E9, 6D, FF, FF, FF, CC, CC, CC, 44, 34, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B4, 36, 00, 00, 80, 30, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, BC, 34, 00, 00, D0, 34, 00, 00, E2, 34, 00, 00, 00, 35, 00, 00, 12, 35, 00, 00, 1C, 35, 00...
 
[+]

Entropy:
6.9885

Code size:
12.1 KB (12,416 bytes)

Driver
Display name:
SREX Secure Guard Manger Service

Service name:
RexCrypt

Description:
SGM Module

Type:
Kernel device driver (KernelDriver)


Scan RexCrypt.sys - Powered by Reason Core Security