spyshelter.sys

Datpol Janusz Siemienowicz

It runs as a Windows kernel mode device driver named “Spyshelter”.
Publisher:
SpyShelter  (signed by Datpol Janusz Siemienowicz)

Product:
SpyShelter

Description:
SpyShelter Driver

Version:
8.2.00.00 built by: Windows

MD5:
b4a41a40ce253037e99b936b298e8003

SHA-1:
7ecb45bfea69ee96690e68999672032fd906c9c6

SHA-256:
12f0797bfcccd5dfadc33db1ab02e5dd454b9efd1aea5fa84c625d9b9b05b0c8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 9:40:22 AM UTC  (today)

File size:
290.8 KB (297,784 bytes)

Product version:
8.2

Original file name:
SpyShelterDrv.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Program Files\spyshelter personal free\spyshelter.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
9/9/2012 2:58:51 AM

Valid to:
11/7/2013 5:09:30 PM

Subject:
E=biuro@datpol.com, CN=Datpol Janusz Siemienowicz, OU=Datpol, O=Datpol Janusz Siemienowicz, L=Olkusz, S=malopolskie, C=PL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121EAB2799A417769A6985740A2E4F3F285

File PE Metadata
Compilation timestamp:
4/4/2013 8:37:52 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
6144:J2AdLsbqJHLjMngWnwFEOVSXyPuTuAICndBzub:4eHvSZIS9uAIC2b

Entry address:
0x93E95

Entry point:
E9, 61, AA, FC, FF, C6, 04, 24, BE, 8D, 64, 24, 34, 0F, 85, 6D, C9, 00, 00, 60, 89, 7C, 24, 1C, 9C, 9C, 89, 5C, 24, 20, 88, 5C, 24, 04, 8D, 64, 24, 20, E8, 0B, D2, 00, 00, 60, 89, F4, 9C, C6, 04, 24, B0, 8D, 64, 24, 04, E9, 56, A8, FC, FF, F5, 8A, 16, 9C, E8, 5E, EE, FE, FF, 6C, E0, 14, B2, D6, 9E, 97, 50, 4C, 5D, 58, 52, 2B, BC, 37, 2E, 17, 11, 1F, 14, 88, 73, A6, B1, 5F, 40, 77, F2, AD, AB, 6B, F5, 09, 8D, CC, 3D, D9, 04, 43, 54, 81, A3, 5F, 4F, 63, C4, 69, DE, 96, A2, E3, 73, AC, 27, 4E, D2, D9, B4, A8...
 
[+]

Packer / compiler:
Xtreme-Protector v1.05

Code size:
116.5 KB (119,296 bytes)

Driver
Display name:
Spyshelter

Description:
Spyshelter driver

Type:
Kernel device driver (KernelDriver)

Group:
FSFilter Activity Monitor

Depends on:
FltMgr


Scan spyshelter.sys - Powered by Reason Core Security