jsdrv.exe

JsDriver

Goobzo LTD

The application jsdrv.exe by Goobzo has been detected as adware by 6 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named SPDriver triggered to execute each time a user logs in.
Publisher:
Goobzo LTD  (signed and verified)

Product:
JsDriver

Version:
1.0.0.18

MD5:
d4252d2b07b76530cfe944acdf83428a

SHA-1:
60eee9305c76a85e94612b685153e9c7fee23b80

SHA-256:
dd76b8dc12800e741a7f5b60db0acba6440dcf766a611f68d3fef256e8c76ec7

Scanner detections:
6 / 68

Status:
Adware

Analysis date:
4/29/2024 11:08:29 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Crypt.XPACK.Gen
7.11.133.122

AVG
MalSign.Skodna
2015.0.3553

Comodo Security
UnclassifiedMalware
17841

Emsisoft Anti-Malware
Gen:Trojan.Heur.DP.bGW@aOzK@qdi
8.14.02.24.03

Reason Heuristics
PUP.Goobzo.Task.F
14.8.8.2

VIPRE Antivirus
Goobzo
26806

File size:
2.8 MB (2,975,592 bytes)

Product version:
1,0,0,18

Copyright:
Copyright (C) 2014

Original file name:
jsdrv.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\shopperpro\jsdriver\1.0.0.18\jsdrv.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/2/1913 3:00:00 AM

Valid to:
5/3/1915 2:59:59 AM

Subject:
CN=Goobzo LTD, O=Goobzo LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
120B25DDE57B88636AD4D97D23B99C88

File PE Metadata
Compilation timestamp:
2/10/2014 11:12:49 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:ASDKpX0Iu2/pdfmw/+8x4Mn7SdkB7J8uJMJRvovFYtU:ASDKSIuuDbxDnquDZ

Entry address:
0x17EB90

Entry point:
55, 8B, EC, E8, 48, 82, 01, 00, E8, 03, 00, 00, 00, 5D, C3, CC, 55, 8B, EC, 6A, FE, 68, 40, 42, 66, 00, 68, C0, 19, 58, 00, 64, A1, 00, 00, 00, 00, 50, 83, C4, E0, 53, 56, 57, A1, 70, 02, 67, 00, 31, 45, F8, 33, C5, 50, 8D, 45, F0, 64, A3, 00, 00, 00, 00, 89, 65, E8, C7, 45, E0, 00, 00, 00, 00, E8, F1, 27, 01, 00, 66, 89, 45, E4, 6A, 02, E8, 26, 81, 01, 00, 83, C4, 04, E8, 3E, 01, 00, 00, 89, 45, D4, E8, 46, 51, 01, 00, 85, C0, 75, 0A, 6A, 1C, E8, BB, 01, 00, 00, 83, C4, 04, E8, F3, 44, 01, 00, 85, C0, 75...
 
[+]

Entropy:
6.0535

Code size:
1.9 MB (1,970,176 bytes)

Scheduled Task
Task name:
SPDriver

Trigger:
Logon (Runs on logon)


Remove jsdrv.exe - Powered by Reason Core Security