spyshelter.sys

Datpol Janusz Siemienowicz

It runs as a Windows 64-bit kernel mode device driver named “Spyshelter”.
Publisher:
SpyShelter  (signed by Datpol Janusz Siemienowicz)

Product:
SpyShelter

Description:
SpyShelter Driver

Version:
9.5.00.00 built by: Windows

MD5:
509e2138bad2bdc2cfbc77b39a4db2fc

SHA-1:
880e1691bc99ec4948cb10989a6ded279ecae832

SHA-256:
7ef05f05aa127a1ee60b67cbc50f073b4388211ff5e828a3f3dab618330dc898

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 9:31:01 AM UTC  (today)

File size:
512.8 KB (525,152 bytes)

Product version:
9.5

Original file name:
SpyShelterDrv.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Program Files\spyshelter\spyshelter.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/26/2014 1:14:04 PM

Valid to:
12/8/2014 5:09:30 PM

Subject:
E=biuro@datpol.com, CN=Datpol Janusz Siemienowicz, O=Datpol Janusz Siemienowicz, L=Olkusz, S=Malopolskie, C=PL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121B2A7BEEB0FC74F69CC135D6161C7095F

File PE Metadata
Compilation timestamp:
10/23/2014 2:30:11 PM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
12288:ggoLRm1hco8LcCHuj5P44HpE2oCNQ9mxu2VnsY2+MOH2:IUrco8ACHSZHpED9mxuHYPW

Entry address:
0x4C064

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, F6, 50, FB, FF, CC, CC, A0, C1, 04, 00, 00, 00, 00, 00, 00, 00, 00, 00, D2, D1, 04, 00, C8, C0, 02, 00, D8, C0, 04, 00, 00, 00, 00, 00, 00, 00, 00, 00, 22, D4, 04, 00, 00, C0, 02, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, E2, D3, 04, 00, 00, 00, 00, 00, C4, D3, 04, 00...
 
[+]

Code size:
175 KB (179,200 bytes)

Driver
Display name:
Spyshelter

Description:
Spyshelter driver

Type:
Kernel device driver (KernelDriver)

Group:
FSFilter Activity Monitor

Depends on:
FltMgr


Scan spyshelter.sys - Powered by Reason Core Security