spyshelter.sys

Datpol Janusz Siemienowicz

It runs as a Windows 64-bit kernel mode device driver named “Spyshelter”.
Publisher:
SpyShelter  (signed by Datpol Janusz Siemienowicz)

Product:
SpyShelter

Description:
SpyShelter Driver

Version:
9.5.00.00 built by: Windows

MD5:
9ae1bb24cd90def36f318a90a4457b32

SHA-1:
987cdd7239ea7bb3dc8bc51d69b815fcecacb8df

SHA-256:
6683015f575c2d861c1908fc4c713c5c1833988845e4971b968559491b5f3b30

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 9:25:25 AM UTC  (today)

File size:
414.3 KB (424,288 bytes)

Product version:
9.5

Original file name:
SpyShelterDrv.sys

File type:
Driver (Win64 SYS)

Common path:
C:\Program Files\spyshelter premium\spyshelter.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/26/2014 3:14:04 PM

Valid to:
12/8/2014 8:09:30 PM

Subject:
E=biuro@datpol.com, CN=Datpol Janusz Siemienowicz, O=Datpol Janusz Siemienowicz, L=Olkusz, S=Malopolskie, C=PL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121B2A7BEEB0FC74F69CC135D6161C7095F

File PE Metadata
Compilation timestamp:
10/23/2014 5:06:10 PM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
12288:ndd0ps30LPnhu9E25IP2KO+3Ek/4qubKCX:n4pdjhFtBOHs4h

Entry address:
0x4A064

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, F6, 70, FB, FF, CC, CC, A0, A1, 04, 00, 00, 00, 00, 00, 00, 00, 00, 00, 98, B1, 04, 00, C8, B0, 02, 00, D8, A0, 04, 00, 00, 00, 00, 00, 00, 00, 00, 00, E8, B3, 04, 00, 00, B0, 02, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, A8, B3, 04, 00, 00, 00, 00, 00, 8A, B3, 04, 00...
 
[+]

Code size:
169.5 KB (173,568 bytes)

Driver
Display name:
Spyshelter

Description:
Spyshelter driver

Type:
Kernel device driver (KernelDriver)

Group:
FSFilter Activity Monitor

Depends on:
FltMgr


Scan spyshelter.sys - Powered by Reason Core Security