spyshelter.sys

Datpol Janusz Siemienowicz

It runs as a Windows kernel mode device driver named “Spyshelter”.
Publisher:
SpyShelter  (signed by Datpol Janusz Siemienowicz)

Product:
SpyShelter

Description:
SpyShelter Driver

Version:
10.8.6.0 built by: Windows

MD5:
37a6cb2d6c26ec343b24078aa553c35d

SHA-1:
ce615c83b9720a3b4bf1cc40559d3aaa82cba71a

SHA-256:
65963b9eca677d9ad048e2b333bc2803b7ce5013a754e5b69db8f3054485d47d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/30/2024 3:33:39 PM UTC  (today)

File size:
1.3 MB (1,415,056 bytes)

Product version:
10.8.6

Copyright:
(C) Datpol. All rights reserved.

Original file name:
SpyShelterDrv.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Program Files\spyshelter premium\spyshelter.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/25/2016 5:55:30 PM

Valid to:
8/26/2017 2:49:24 PM

Subject:
CN=Datpol Janusz Siemienowicz, O=Datpol Janusz Siemienowicz, L=OLKUSZ, C=PL

Issuer:
CN=GlobalSign CodeSigning CA - G3, O=GlobalSign nv-sa, C=BE

Serial number:
7F3EA61EAE04BAEDC14B924C

File PE Metadata
Compilation timestamp:
10/28/2016 11:17:09 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
24576:zURdriCcJgkNG1fkE6RNmAT6u1zHoJWUroTy/K040Uq:961fkEa4AT6OMJETyG0Uq

Entry address:
0x2CB593

Entry point:
68, 7F, 90, E0, E6, E8, 4D, EF, EE, FF, C2, 0C, 00, FF, FF, FF, FF, A4, A8, 2D, 00, DB, 48, 2F, 00, FF, FF, FF, FF, AD, A6, 2F, 00, 42, A0, 30, 00, 32, D1, 76, 33, 91, 51, 4F, ED, 03, 1A, B6, 70, 0D, 96, 12, C1, E8, 14, F9, 66, A2, 0C, 37, 18, E1, 30, C1, FF, CA, EB, FC, 56, 1A, 64, 44, EB, 99, 1E, E3, 98, 15, 7B, CE, 66, AB, 44, 37, 65, 13, D8, 4D, E3, 27, D1, 1A, 55, 8E, BF, BB, 81, 9A, 9F, 63, 9F, 13, D1, 62, A3, A8, 52, 18, E4, FE, 78, D1, 1C, BE, 99, AA, 3B, 99, FF, 7A, 05, 9C, BC, 84, 3C, 67, ED, DC...
 
[+]

Entropy:
7.9784  (probably packed)

Code size:
170.5 KB (174,592 bytes)

Driver
Display name:
Spyshelter

Description:
Spyshelter driver

Type:
Kernel device driver (KernelDriver)

Group:
FSFilter Activity Monitor

Depends on:
FltMgr


Scan spyshelter.sys - Powered by Reason Core Security