USBlyzer.sys

USBlyzer Capture Driver

USBlyzer

It runs as a Windows 64-bit kernel mode device driver named “USBlyzer Capture Driver”.
Publisher:
USBlyzer Team  (signed by USBlyzer)

Product:
USBlyzer Capture Driver

Version:
2.0.0.20

MD5:
342b39350be55fbd56c309e513e97a59

SHA-1:
b27d7ef18c8e2b6c583c4c551c3c3c437ade55e8

SHA-256:
84ed153a13c4b54570c3223d79838b870ad2ced77d940576f188eae10713d537

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 4:59:58 PM UTC  (today)

File size:
97.2 KB (99,488 bytes)

Product version:
2.0.0.20

Copyright:
Copyright © 2006-2011 USBlyzer

Original file name:
USBlyzer.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\usblyzer.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/17/2011 2:00:00 AM

Valid to:
7/2/2013 1:59:59 AM

Subject:
CN=USBlyzer, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=USBlyzer, L=St. Petersburg, S=St. Petersburg, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
05C6ED42D30A0CB88EDB1C747F6C9324

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
1536:t3YwqLZeK3CoClUC4ipEa4cJFMqkqEYzluKYFeqG3mqJ7eMJmFxo0:t3Ywqw6ipERFe/267eMcFD

Entry point:
8B, FF, 55, 8B, EC, A1, 94, DB, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1A, A1, DC, C5, 01, 00, 8B, 00, 35, 94, DB, 01, 00, A3, 94, DB, 01, 00, 75, 07, 8B, C1, A3, 94, DB, 01, 00, F7, D0, A3, 98, DB, 01, 00, 5D, E9, D2, FD, FF, FF, 4C, 00, 6F, 00, 67, 00, 50, 00, 6F, 00, 6C, 00, 6C, 00, 69, 00, 6E, 00, 67, 00, 49, 00, 6E, 00, 74, 00, 65, 00, 72, 00, 76, 00, 61, 00, 6C, 00, 00, 00, 4D, 00, 65, 00, 6D, 00, 6F, 00, 72, 00, 79, 00, 55, 00, 73, 00, 61, 00, 67, 00, 65, 00, 4C, 00, 69, 00, 6D, 00...
 
[+]

Entropy:
6.2071

Driver
Display name:
USBlyzer Capture Driver

Service name:
USBlyzer

Type:
Kernel device driver (KernelDriver)


Scan USBlyzer.sys - Powered by Reason Core Security