spyshelter.sys

Datpol Janusz Siemienowicz

It runs as a Windows kernel mode device driver named “Spyshelter”.
Publisher:
SpyShelter  (signed by Datpol Janusz Siemienowicz)

Product:
SpyShelter

Description:
SpyShelter Driver

Version:
9.4.00.00 built by: Windows

MD5:
98eb3a932f3d05492e921824d2c01128

SHA-1:
09a91b2fdfdfcdb9a2e0faf0e39bbbb22c624068

SHA-256:
1f30dbdef0026a6fe40e9cb3b79ca126627a4d9c0658df10d20f5316332397ed

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 9:24:44 AM UTC  (today)

File size:
226.3 KB (231,776 bytes)

Product version:
9.4

Original file name:
SpyShelterDrv.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Program Files\spyshelter personal free\spyshelter.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/26/2014 1:14:04 PM

Valid to:
12/8/2014 5:09:30 PM

Subject:
E=biuro@datpol.com, CN=Datpol Janusz Siemienowicz, O=Datpol Janusz Siemienowicz, L=Olkusz, S=Malopolskie, C=PL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121B2A7BEEB0FC74F69CC135D6161C7095F

File PE Metadata
Compilation timestamp:
10/7/2014 6:12:23 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
6144:zNT8RoTK1MT61+OgLXbW1/5ETHJzaP3PbT:lmM+cOALWJQU/bT

Entry address:
0x5757F

Entry point:
9C, 8D, 64, 24, 04, 0F, 8A, 63, C7, 01, 00, 9C, C7, 04, 24, 6D, A7, 7D, CA, E9, 3B, BC, 01, 00, F9, F5, F6, D0, 66, 81, FB, 3C, 10, 04, 06, F5, F9, C0, C8, 04, F9, F6, D0, 66, 81, F9, D5, 95, F5, D1, E8, E9, 75, CD, FF, FF, 00, 00, 49, 6F, 43, 72, 65, 61, 74, 65, 44, 65, 76, 69, 63, 65, 00, 8D, 64, 24, 2C, E8, 85, AA, 01, 00, 9C, 9C, 52, 8D, 64, 24, 0C, 0F, 80, 3A, CF, FF, FF, 0F, 83, 6D, CC, FF, FF, 9C, B3, 02, 60, FF, 74, 24, 04, C6, 04, 24, 6A, 41, E9, A4, 05, 03, 00, 00, 00, 46, 6C, 74, 46, 72, 65, 65...
 
[+]

Code size:
128 KB (131,072 bytes)

Driver
Display name:
Spyshelter

Description:
Spyshelter driver

Type:
Kernel device driver (KernelDriver)

Group:
FSFilter Activity Monitor

Depends on:
FltMgr


Scan spyshelter.sys - Powered by Reason Core Security