Our call: Is keylog.sys safe?Malicious
- 1 high-confidence signature or behavior rule matched this file.Observed · Signature and behavior rules
- 11 of 75 antivirus engines flagged the file, including BitDefender and CTX.Observed · Antivirus analysis
- The file has a valid code signature from Microsoft Windows Hardware Compatibility Publisher.Observed · Code-signing metadata
bb1b4e46f1e4a7f17b…e2656ba48bRecommended next actions
Before using
Do not use it. Quarantine this component with your antivirus, then remove or repair it through the official driver, firmware, or device-software package. Do not delete the driver or firmware file manually.
If you already used it
Disconnect from the internet, start a full or offline antivirus scan, then secure important accounts from a clean device.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete11 of 75 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
Complete1 signature or behavior rule matched.
External intel
Partial1 of 3 independent reference sources completed.
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceObservedSourceSignature and behavior rulesObserved at - 02
11 of 75 antivirus engines flagged the file, including BitDefender and CTX.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The file has a valid code signature from Microsoft Windows Hardware Compatibility Publisher.
ProvenanceObservedSourceCode-signing metadataObserved at
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
No saved analyst narrative
This report keeps the verified scan facts available below without inventing an analysis that was not saved with the scan.
Behavior
Plain-English impact first, then the observed runtime evidence.
Threat context
How trojans work
A trojan disguises itself as something useful or harmless to trick you into running it. Once open, it does its real job in the background — anything from stealing data to opening a back door or downloading more malware.
Bottom line:The disguise is the whole trick, so a trustworthy-looking name or icon means nothing.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Detection sources at a glance
Category: generic-trojan
One or more independent reference databases matched this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
- PE_Digital_Certificate
11 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- keylog.sys
- Format
- Win32 EXE
- Code signing
- Signature valid: Microsoft Windows Hardware Compatibility Publisher
- Size
- 52.7 KB
- Last analyzed
- Jun 4, 2026, 3:47 PM UTC
bb1b4e46f1e4a7f17b1b04ee08c33400b2b6fd2327612a4d84da81e2656ba48bSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
Don't use this component. Quarantine this component with your antivirus, then remove or repair it through the official driver, firmware, or device-software package. Do not delete the driver or firmware file manually.
If you already used it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
If you typed any passwords while it was open, change them from a device you trust.
Get a fresh driver or firmware package from the hardware or software manufacturer's official site.