arta64.sys

Sheed Antivirus (not for sale/use outside IRAN)

SheedSoftLtd

It runs as a Windows 64-bit file system device driver named “ArtaFilter”.
Publisher:
SheedSoft Ltd.  (signed by SheedSoftLtd)

Product:
Sheed Antivirus (not for sale/use outside IRAN)

Description:
Sheed Arta File System Filter Driver

Version:
1.0 built by: WinDDK

MD5:
f645156cfa36c6470c55b6361bec07c3

SHA-1:
563b5e1249ed72febc006520e89c2b86eda5d3a2

SHA-256:
e88b37e9730d21bd4cab49823606571f98c108f54ce4e7ef1e1184fb6475dc80

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 9:49:40 AM UTC  (today)

File size:
85.9 KB (87,912 bytes)

Product version:
6.1.7600.16385

Copyright:
© Sheedsoft Corporation. All rights reserved.

Original file name:
arta.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\arta64.sys

Digital Signature
Signed by:

Authority:
SheedSoftLtd

Valid from:
4/18/2012 1:30:43 AM

Valid to:
12/31/2039 3:59:59 PM

Subject:
CN=SheedSoftLtd

Issuer:
CN=SheedSoftLtd

Serial number:
B8E2EE2B341DD9894BEAE151FB7071E6

File PE Metadata
Compilation timestamp:
6/11/2012 4:19:09 PM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
1536:BtVk2AmL8cp7Bz6K48gOWIUOHjGXYEoP1ZGwgBX:BtxBz6K4nOpLjL1ZGwg

Entry address:
0x1BC0C

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, DE, F3, FF, FF, CC, CC, CC, CC, CC, CC, 5C, 00, 52, 00, 45, 00, 47, 00, 49, 00, 53, 00, 54, 00, 52, 00, 59, 00, 5C, 00, 4D, 00, 41, 00, 43, 00, 48, 00, 49, 00, 4E, 00, 45, 00, 5C, 00, 53, 00, 59, 00, 53, 00, 54, 00, 45, 00, 4D, 00, 5C, 00, 43, 00, 6F, 00, 6E, 00, 74, 00, 72, 00, 6F, 00, 6C, 00, 53, 00, 65, 00, 74, 00, 30, 00, 30, 00, 31, 00, 5C, 00, 53, 00, 65, 00, 72, 00, 76, 00, 69, 00, 63, 00, 65, 00...
 
[+]

Entropy:
5.8146

Code size:
47.5 KB (48,640 bytes)

Driver
Display name:
ArtaFilter

Description:
Sheed Antivirus Arta Filter Driver

Type:
File system 'filter' driver (FileSystemDriver)

Group:
FSFilter Activity Monitor


Scan arta64.sys - Powered by Reason Core Security