spyshelter.sys

Datpol Janusz Siemienowicz

It runs as a Windows kernel mode device driver named “Spyshelter”.
Publisher:
SpyShelter  (signed by Datpol Janusz Siemienowicz)

Product:
SpyShelter

Description:
SpyShelter Driver

Version:
5.40.00.00 built by: Windows

MD5:
fa0a0bf4e55d2cef998e599e3c841f62

SHA-1:
e5e52a68c8fd57aea03d37cc7c9e64c24fe43b0f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/4/2024 5:12:00 PM UTC  (today)

File size:
171 KB (175,088 bytes)

Product version:
5.40

Original file name:
SpyShelterDrv.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Program Files\spyshelter premium\spyshelter.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/3/2010 11:15:25 AM

Valid to:
10/11/2011 12:28:58 PM

Subject:
CN=Datpol Janusz Siemienowicz, OU=Datpol Janusz Siemienowicz, O=Datpol Janusz Siemienowicz, L=Olkusz, S=malopolskie, C=PL

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012A38848FCA

File PE Metadata
Compilation timestamp:
8/11/2011 5:13:20 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
3072:VCBl/H5KSEYggP6wKGjKVXMwDK9g8PvnfPqSY11k1W+O:VCBDDEwP6wJMcwDagEHCSY7uW

Entry address:
0x545C9

Entry point:
E8, 48, 03, FF, FF, 00, 00, 52, 74, 6C, 43, 72, 65, 61, 74, 65, 55, 6E, 69, 63, 6F, 64, 65, 53, 74, 72, 69, 6E, 67, 00, 00, 00, 4B, 65, 55, 6E, 73, 74, 61, 63, 6B, 44, 65, 74, 61, 63, 68, 50, 72, 6F, 63, 65, 73, 73, 00, 48, 41, 4C, 2E, 64, 6C, 6C, 00, 00, 00, 52, 74, 6C, 50, 72, 65, 66, 69, 78, 55, 6E, 69, 63, 6F, 64, 65, 53, 74, 72, 69, 6E, 67, 00, E8, 6C, EB, FE, FF, 68, 88, 43, ED, 4D, FF, 30, 8F, 44, 24, 2C, 9C, 9C, FF, 74, 24, 34, C2, 38, 00, 8D, 64, 24, 10, 0F, 85, 9C, 06, FF, FF, 9C, 60, 60, 9C, 89...
 
[+]

Code size:
143.5 KB (146,944 bytes)

Driver
Display name:
Spyshelter

Description:
Spyshelter driver

Type:
Kernel device driver (KernelDriver)

Group:
FSFilter Activity Monitor

Depends on:
FltMgr


Scan spyshelter.sys - Powered by Reason Core Security