spyshelter.sys

Datpol Janusz Siemienowicz

It runs as a Windows kernel mode device driver named “Spyshelter”.
Publisher:
SpyShelter  (signed by Datpol Janusz Siemienowicz)

Product:
SpyShelter

Description:
SpyShelter Driver

Version:
4.20.00.00 built by: Windows

MD5:
781c685dbaf9834abb415d284f224f14

SHA-1:
51c94f883556732b4d87ebd7709ff78c3cb054f8

SHA-256:
287d317fb98c3eb56937641bd457abff1ea4689b6d070db4df11cf3ef33e78ef

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/4/2024 5:01:52 PM UTC  (today)

File size:
162.8 KB (166,712 bytes)

Product version:
4.20

Original file name:
SpyShelterDrv.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Program Files\spyshelter personal free\spyshelter.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/7/2011 6:09:31 PM

Valid to:
10/7/2012 6:09:31 PM

Subject:
E=biuro@datpol.com, CN=Datpol Janusz Siemienowicz, OU=Datpol, O=Datpol Janusz Siemienowicz, L=Olkusz, S=malopolskie, C=PL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121ECF13B8CE637B81F878ED4D17A65C14B

File PE Metadata
Compilation timestamp:
10/21/2011 2:29:35 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
3072:6jjtFjFMKtvkhC0KnKZV9UhnYzzBT1ao/1oc2U6s7Urv:6jjDftcC0oKZHEneRwo/LyaE

Entry address:
0x42989

Entry point:
60, 60, 9C, C7, 44, 24, 40, FF, 64, 31, FE, 52, E8, 22, 0E, 00, 00, FF, 34, 24, C7, 44, 24, 38, 93, 37, 05, 00, 68, 3A, 9A, E9, 3F, FF, 30, 8F, 44, 24, 38, 88, 14, 24, 9C, FF, 74, 24, 3C, C2, 40, 00, FE, C2, 00, F2, 8D, 14, 85, F1, 86, 88, F8, 55, 0F, 9A, C6, 89, E5, 66, F7, DA, F8, 50, 66, D1, CA, 42, 68, FF, 15, 63, F5, 87, 0C, 24, 66, 0F, BB, D2, 53, 66, 0F, BD, D1, 38, F6, C0, CD, 06, 57, 66, 0F, BC, C8, 81, FF, 1C, AF, F4, 4C, 66, 0F, BB, D2, 66, 0F, BA, EA, 08, 56, 66, D1, CE, C1, CA, 03, 66, 0F, BC...
 
[+]

Code size:
144 KB (147,456 bytes)

Driver
Display name:
Spyshelter

Description:
Spyshelter driver

Type:
Kernel device driver (KernelDriver)

Group:
FSFilter Activity Monitor

Depends on:
FltMgr


Scan spyshelter.sys - Powered by Reason Core Security