spyshelter.sys

Datpol Janusz Siemienowicz

It runs as a Windows kernel mode device driver named “Spyshelter”.
Publisher:
SpyShelter  (signed by Datpol Janusz Siemienowicz)

Product:
SpyShelter

Description:
SpyShelter Driver

Version:
5.14.00.00 built by: Windows

MD5:
0a59ac74c4bde6d84b2cbd7a1d48177b

SHA-1:
30321bdc11cc93b23fbcf60370c7c543ecc33e5c

SHA-256:
65891d8d83350c9023959eb6a0f533b08b7dbd1973b1de3d373caae0b6432964

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/27/2024 9:30:24 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Packed
1.3.0.6379

File size:
167 KB (170,992 bytes)

Product version:
5.14

Original file name:
SpyShelterDrv.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Program Files\spyshelter premium\spyshelter.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/3/2010 4:15:25 PM

Valid to:
10/11/2011 5:28:58 PM

Subject:
CN=Datpol Janusz Siemienowicz, OU=Datpol Janusz Siemienowicz, O=Datpol Janusz Siemienowicz, L=Olkusz, S=malopolskie, C=PL

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012A38848FCA

File PE Metadata
Compilation timestamp:
4/6/2011 10:53:01 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
3072:c/a3dYfftaHJdsFL92m+f4U8H/dRiRsCNrig34EvcGTopVKum6gj:F3qqJ8p1+f4U8H/de5ZwGsaum6g

Entry address:
0x4E65F

Entry point:
9C, E9, 18, 3F, FF, FF, 3A, 07, E8, 53, FD, FF, FF, 00, 00, 50, 73, 47, 65, 74, 54, 68, 72, 65, 61, 64, 54, 65, 62, 00, E9, AB, FF, FF, FF, 8D, 64, 24, 28, 0F, 85, 75, 1A, 01, 00, F9, 66, 87, CE, 66, 0F, C1, CE, 89, F9, 66, 0F, B3, F6, 66, 0F, BC, F1, 29, D9, 53, 66, F7, D6, E9, FC, 33, 01, 00, E8, E4, 30, 01, 00, 0F, 91, C3, 83, C6, 08, 80, D7, F8, 80, E7, 50, 66, 8B, 1E, F8, E8, D4, 82, 01, 00, 00, 00, 52, 74, 6C, 47, 65, 74, 41, 63, 65, 00, 9C, 8D, 64, 24, 0C, 0F, 83, EA, 3F, 01, 00, F8, F6, C6, 27, 80...
 
[+]

Code size:
139.5 KB (142,848 bytes)

Driver
Display name:
Spyshelter

Description:
Spyshelter driver

Type:
Kernel device driver (KernelDriver)

Group:
FSFilter Activity Monitor

Depends on:
FltMgr


Scan spyshelter.sys - Powered by Reason Core Security