arta.sys

Sheed Antivirus (not for sale/use outside IRAN)

SheedSoftLtd

It runs as a Windows 64-bit file system device driver named “ArtaFilter”.
Publisher:
SheedSoft Ltd.  (signed by SheedSoftLtd)

Product:
Sheed Antivirus (not for sale/use outside IRAN)

Description:
Sheed Arta File System Filter Driver

Version:
1.0 built by: WinDDK

MD5:
5aa25dda5e66c942a6547c0fb9061637

SHA-1:
d256d9e159866a96779706328b055a44e38e6abf

SHA-256:
b2578a48870ebb55cdb1bf17083e5630a997d94b5ef0331bac49d3c27c56e154

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/18/2024 2:54:02 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/FakeAV.Sheed.I
7.11.111.42

Bkav FE
HW32.Nonim
1.3.0.4261

File size:
76.2 KB (77,992 bytes)

Product version:
6.1.7600.16385

Copyright:
© Sheedsoft Corporation. All rights reserved.

Original file name:
arta.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\arta.sys

Digital Signature
Signed by:

Authority:
SheedSoftLtd

Valid from:
4/18/2012 12:00:43 PM

Valid to:
1/1/2040 3:29:59 AM

Subject:
CN=SheedSoftLtd

Issuer:
CN=SheedSoftLtd

Serial number:
B8E2EE2B341DD9894BEAE151FB7071E6

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
1536:2UI3tVgTrJAektueblzGXihN9LyITsAYfd:QdVgTrJRktRzVh/+IfK

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 7C, FA, FF, FF, 52, 00, 74, 00, 6C, 00, 47, 00, 65, 00, 74, 00, 56, 00, 65, 00, 72, 00, 73, 00, 69, 00, 6F, 00, 6E, 00, 00, 00, 49, 00, 6F, 00, 47, 00, 65, 00, 74, 00, 41, 00, 74, 00, 74, 00, 61, 00, 63, 00, 68, 00, 65, 00, 64, 00, 44, 00, 65, 00, 76, 00, 69, 00, 63, 00, 65, 00, 52, 00, 65, 00, 66, 00, 65, 00, 72, 00, 65, 00, 6E, 00, 63, 00, 65, 00, 00, 00, 49, 00, 6F, 00, 47, 00, 65, 00, 74, 00, 44, 00, 69, 00, 73, 00, 6B, 00, 44, 00, 65, 00, 76, 00, 69, 00...
 
[+]

Entropy:
5.9831

Driver
Display name:
ArtaFilter

Description:
Sheed Antivirus Arta Filter Driver

Type:
File system 'filter' driver (FileSystemDriver)

Group:
FSFilter Activity Monitor


Scan arta.sys - Powered by Reason Core Security