SpyShelterKb.sys

Datpol Janusz Siemienowicz

It runs as a Windows 64-bit kernel mode device driver named “SpyshelterKb”.
Publisher:
SpyShelter  (signed by Datpol Janusz Siemienowicz)

Product:
SpyShelter

Description:
SpyShelter Additional Driver

Version:
3.1.00.00 built by: WinDDK

MD5:
4336027bf36eccec3da3fe465cad8320

SHA-1:
8afa5e710db51d7dbeb628665828ad8cccd7d86a

SHA-256:
5ee197680b6ea6488022c9d1168470ebaa9a202bff622638e259e12d425390b8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 11:14:02 AM UTC  (today)

File size:
249.3 KB (255,328 bytes)

Product version:
3.1

Original file name:
SpyShelterKb.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Program Files\spyshelter premium\spyshelterkb.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/1/2013 5:08:56 AM

Valid to:
12/8/2014 11:09:30 AM

Subject:
E=biuro@datpol.com, CN=Datpol Janusz Siemienowicz, O=Datpol Janusz Siemienowicz, L=Olkusz, S=Malopolskie, C=PL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112176D4B94E84F997B75286D5F8613C2EFD

File PE Metadata
Compilation timestamp:
6/28/2014 8:54:31 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
6144:OrUzj3IabcsnbjGhjjgAvBN6AiuDQNqwtuqXYLu5WK7sRzCq8:eU33IaEB1BPiPZt9ojx38

Entry address:
0x8344B

Entry point:
E9, 69, 60, FE, FF, E9, F6, 5E, 00, 00, F8, F9, F5, F2, AE, E9, DC, 44, 00, 00, E9, E2, 42, FE, FF, E8, 7C, 4E, FD, FF, E9, D1, 50, 00, 00, 0F, 84, CC, 96, 00, 00, 81, D9, 7D, C5, 6D, FF, 66, 0F, BC, CC, 66, FF, C9, 48, 0F, A4, C1, 06, 50, F9, 48, 89, D9, 48, 0F, A4, F8, 06, C0, E4, 05, 48, 83, EC, 20, 48, 8D, 86, 8C, 2B, 19, 94, 0F, 90, C4, 66, 0F, C8, 48, 8D, 05, B5, 86, 00, 00, E9, A0, 36, FE, FF, E9, 2E, 35, FE, FF, 09, C3, 87, 7F, 75, 95, 1F, 79, 5C, E7, E1, 6B, A6, 76, B3, 8B, 38, 43, F5, 57, D2, 19...
 
[+]

Entropy:
7.8279

Packer / compiler:
Xtreme-Protector v1.05

Code size:
52 KB (53,248 bytes)

Driver
Display name:
SpyshelterKb

Type:
Kernel device driver (KernelDriver)

Depends on:
SpyShelter


Scan SpyShelterKb.sys - Powered by Reason Core Security