spyshelter.sys

Datpol Janusz Siemienowicz

It runs as a Windows kernel mode device driver named “Spyshelter”.
Publisher:
SpyShelter  (signed by Datpol Janusz Siemienowicz)

Product:
SpyShelter

Description:
SpyShelter Driver

Version:
9.2.00.00 built by: Windows

MD5:
50807dc5a58ac27220a0cbfd19a5229c

SHA-1:
7c0bc9b0b619dfa01a18a623d605047e3fdb2159

SHA-256:
1f686011d51637c1bdce14e91cce9e09a208f038bb888ab274ec48545cb8bee2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/4/2025 4:07:35 AM UTC  (today)

File size:
448.3 KB (459,104 bytes)

Product version:
9.2

Original file name:
SpyShelterDrv.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Program Files\spyshelter firewall\spyshelter.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/26/2014 4:14:04 AM

Valid to:
12/8/2014 8:09:30 AM

Subject:
E=biuro@datpol.com, CN=Datpol Janusz Siemienowicz, O=Datpol Janusz Siemienowicz, L=Olkusz, S=Malopolskie, C=PL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121B2A7BEEB0FC74F69CC135D6161C7095F

File PE Metadata
Compilation timestamp:
9/18/2014 10:00:34 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
12288:7DdTuY2xFyuYNJoIPErpYWUgaARA7z4fmfTVN:7Dxa9YDoIEpZG7zN3

Entry address:
0xAE100

Entry point:
E9, 0F, 92, FD, FF, 68, E6, 92, 9D, 08, 60, 60, 68, DA, 8C, BE, 5E, 8D, 64, 24, 44, E9, 27, 5C, 04, 00, 66, 89, 04, 24, E8, 08, 95, FF, FF, F6, D6, 8D, 53, 04, 0F, CF, 8B, 7D, 08, E9, EF, BF, FD, FF, 8D, 64, 24, 2C, 0F, 84, E3, 31, 04, 00, E8, 35, 36, 04, 00, 54, E8, F1, 1E, 04, 00, C7, 44, 24, 0C, 93, 7D, 0B, 00, 60, 55, FF, 30, 8F, 44, 24, 2C, 88, 7C, 24, 08, 89, 4C, 24, 10, C6, 44, 24, 04, 90, FF, 74, 24, 2C, C2, 30, 00, 72, B0, C2, 8F, CB, 2E, 84, 03, 95, 6C, F3, AB, C4, EB, 8C, 00, 2B, 62, B2, 7F, 4C...
 
[+]

Entropy:
7.8960

Packer / compiler:
Xtreme-Protector v1.05

Code size:
137.5 KB (140,800 bytes)

Driver
Display name:
Spyshelter

Description:
Spyshelter driver

Type:
Kernel device driver (KernelDriver)

Group:
FSFilter Activity Monitor

Depends on:
FltMgr


Scan spyshelter.sys - Powered by Reason Core Security