spyshelter.sys

Datpol Janusz Siemienowicz

It runs as a Windows 64-bit kernel mode device driver named “Spyshelter”.
Publisher:
SpyShelter  (signed by Datpol Janusz Siemienowicz)

Product:
SpyShelter

Description:
SpyShelter Driver

Version:
10.1.0.0 built by: Windows

MD5:
3fb5f9117a63ae0f76761fd64cd93432

SHA-1:
a6f90c2d3e7783f22da3e219af70cbaa9c19509f

SHA-256:
a2ce581c043df44adb543dd561c67c055fe17b042dfa74df052cfc91e7cf8c56

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/30/2024 6:34:59 AM UTC  (today)

File size:
1.1 MB (1,147,144 bytes)

Product version:
10.1

Copyright:
(C) Datpol. All rights reserved.

Original file name:
SpyShelterDrv.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Program Files\spyshelter premium\spyshelter.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/5/2014 1:08:03 PM

Valid to:
1/8/2016 11:09:30 AM

Subject:
E=biuro@datpol.com, CN=Datpol Janusz Siemienowicz, O=Datpol Janusz Siemienowicz, L=Olkusz, S=Malopolskie, C=PL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121D2FCC60F24553FA9E8F529B814703D51

File PE Metadata
Compilation timestamp:
8/28/2015 7:45:38 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
24576:4UDDjZT5jS7blxTTSGlqE/1ey09cdmrGWLpg0q84VaEA:jVT5j+TXqeq9yo/Rt

Entry address:
0x17CD5E

Entry point:
68, C8, 53, 53, 8E, E8, 5F, B1, 0F, 00, 00, 00, 4D, 6D, 43, 72, 65, 61, 74, 65, 53, 65, 63, 74, 69, 6F, 6E, 00, 96, CE, 24, 95, 1B, 9E, 47, 56, 6D, EC, 46, 81, 21, 1A, 34, 70, DF, 12, E5, FD, F0, F0, 64, DD, 7D, 6E, 62, 85, 1D, 1C, 85, F4, B2, C2, 08, 73, F0, F8, E2, 01, F3, F8, BA, 25, 81, 58, 15, 2A, C2, D5, 34, 45, 14, F2, 46, B8, ED, 83, 35, 35, F8, 66, 57, 6D, 8A, 68, A0, 20, 1A, 1A, 4E, FE, 13, E5, C3, 06, D1, 65, DD, 8B, 00, 43, 84, 1D, 72, B3, D5, B3, C2, 3E, FD, D1, F9, E2, 8F, E5, D9, BB, 25, 97...
 
[+]

Entropy:
7.9457  (probably packed)

Code size:
1.1 MB (1,140,224 bytes)

Driver
Display name:
Spyshelter

Description:
Spyshelter driver

Type:
Kernel device driver (KernelDriver)

Group:
FSFilter Activity Monitor

Depends on:
FltMgr


Scan spyshelter.sys - Powered by Reason Core Security