× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: ea6e8e6b0b4c5c3df247751fab5acbdd557384f897ce189a2e788ddef8aa05c4
File name: nCryptPro Driver
Detection ratio: 0 / 67
Analysis date: 2018-03-14 22:41:07 UTC ( 8 months ago )
Antivirus Result Update
Ad-Aware 20180314
AegisLab 20180314
AhnLab-V3 20180314
Alibaba 20180314
ALYac 20180314
Antiy-AVL 20180314
Arcabit 20180314
Avast 20180314
Avast-Mobile 20180314
AVG 20180314
Avira (no cloud) 20180314
AVware 20180314
Baidu 20180314
BitDefender 20180314
Bkav 20180314
CAT-QuickHeal 20180314
ClamAV 20180314
CMC 20180314
Comodo 20180314
CrowdStrike Falcon (ML) 20170201
Cybereason None
Cylance 20180314
Cyren 20180314
DrWeb 20180314
eGambit 20180314
Emsisoft 20180314
Endgame 20180308
ESET-NOD32 20180314
F-Prot 20180314
F-Secure 20180314
Fortinet 20180314
GData 20180314
Ikarus 20180314
Sophos ML 20180121
Jiangmin 20180314
K7AntiVirus 20180314
K7GW 20180314
Kaspersky 20180314
Kingsoft 20180314
Malwarebytes 20180314
MAX 20180314
McAfee 20180314
McAfee-GW-Edition 20180314
Microsoft 20180314
eScan 20180314
NANO-Antivirus 20180314
nProtect 20180314
Palo Alto Networks (Known Signatures) 20180314
Panda 20180314
Qihoo-360 20180314
Rising 20180314
SentinelOne (Static ML) 20180225
Sophos AV 20180314
SUPERAntiSpyware 20180314
Symantec 20180314
Symantec Mobile Insight 20180311
Tencent 20180314
TheHacker 20180311
TotalDefense 20180314
TrendMicro 20180314
TrendMicro-HouseCall 20180314
Trustlook 20180314
VBA32 20180314
VIPRE 20180314
ViRobot 20180314
Webroot 20180314
WhiteArmor 20180223
Yandex 20180314
Zillya 20180314
ZoneAlarm by Check Point 20180314
Zoner 20180314
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Native subsystem.
FileVersionInfo properties
Copyright
Copyright (C) 2006

Product n-Crypt Pro
Original name nCryptPro
Internal name nCryptPro Driver
File version 1, 0, 0, 2
Description nCryptPro Driver
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2006-10-20 11:00:33
Entry Point 0x0002B6B2
Number of sections 6
PE sections
PE imports
IoFreeIrp
RtlInitUnicodeString
ZwReadFile
MmMapLockedPagesSpecifyCache
_allmul
IoGetDeviceObjectPointer
KeInitializeEvent
_snwprintf
ZwQuerySymbolicLinkObject
DbgPrint
IoSetHardErrorOrVerifyDevice
MmBuildMdlForNonPagedPool
KeSetPriorityThread
_except_handler3
KeInitializeSemaphore
KeInitializeMutex
memset
IoBuildDeviceIoControlRequest
IoCreateDevice
ExfInterlockedRemoveHeadList
wcslen
IoDeleteDevice
IoRegisterShutdownNotification
wcsncat
IoGetCurrentProcess
IoAllocateMdl
MmUnmapLockedPages
ExAllocatePoolWithTag
KeClearEvent
PsTerminateSystemThread
KeGetCurrentThread
ZwCreateFile
IofCompleteRequest
IoDeleteSymbolicLink
wcsncpy
_alldiv
KeSetEvent
ExfInterlockedInsertTailList
wcscat
ObReferenceObjectByHandle
KeWaitForSingleObject
KeReleaseSemaphore
ExFreePoolWithTag
KeBugCheck
IoAllocateIrp
ZwSetInformationFile
IoFileObjectType
ZwOpenSymbolicLinkObject
KeReleaseMutex
IoCreateSymbolicLink
ObOpenObjectByPointer
IoGetRelatedDeviceObject
PsCreateSystemThread
memcpy
wcscpy
_aullshr
KeInitializeSpinLock
wcsstr
DbgBreakPoint
ObfDereferenceObject
IofCallDriver
ZwQueryInformationFile
ZwClose
IoFreeMdl
MmUnlockPages
Number of PE resources by type
RT_VERSION 1
Number of PE resources by language
RUSSIAN 1
PE resources
ExifTool file metadata
LegalTrademarks
n-Crypt, n-Crypt Pro

SubsystemVersion
4.0

LinkerVersion
7.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
1.0.0.2

LanguageCode
Unknown (0009)

FileFlagsMask
0x0017

FileDescription
nCryptPro Driver

CharacterSet
Unicode

InitializedDataSize
40352

EntryPoint
0x2b6b2

OriginalFileName
nCryptPro

MIMEType
application/octet-stream

LegalCopyright
Copyright (C) 2006

FileVersion
1, 0, 0, 2

TimeStamp
2006:10:20 12:00:33+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
nCryptPro Driver

ProductVersion
1, 0, 0, 2

UninitializedDataSize
0

OSVersion
4.0

FileOS
Win32

Subsystem
Native

MachineType
Intel 386 or later, and compatibles

CompanyName
n-Trance Security Ltd.

CodeSize
145632

ProductName
n-Crypt Pro

ProductVersionNumber
1.0.0.2

FileTypeExtension
exe

ObjectFileType
Unknown

File identification
MD5 74856edae899fde98a1c9d128fbde33a
SHA1 1517c7ee4ec3349afa4a5b88c2c64d53aea35a35
SHA256 ea6e8e6b0b4c5c3df247751fab5acbdd557384f897ce189a2e788ddef8aa05c4
ssdeep
3072:qV8RMaNvfMqqDL2/jz5Hafu9spnf0X9NGOJwm9f3bpcR83:pxl0qqDL6f5Hafu9sxf0tNGOCm9GC3

authentihash be23eff81dddc3c5d60cb22bfd89786dbb6fbcb73c4b6942856a85e248a4999d
imphash 29557ea09402c7919ac7723835c679b8
File size 182.3 KB ( 186720 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (native) Intel 80386 32-bit

TrID Win32 Executable (generic) (42.7%)
OS/2 Executable (generic) (19.2%)
Generic Win/DOS Executable (18.9%)
DOS Executable Generic (18.9%)
Tags
peexe native

VirusTotal metadata
First submission 2009-04-29 14:32:08 UTC ( 9 years, 6 months ago )
Last submission 2013-02-25 14:35:59 UTC ( 5 years, 8 months ago )
File names file-3280430_sy_
nCryptPro
ncryptpro.sys
file-2878412_sys
ncryptpro.sys
nCryptPro Driver
ncryptpro.sys
74856EDAE899FDE98A1C9D128FBDE33A
ncryptpro.sys
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!