jsdrv.exe

JsDriver

The application jsdrv.exe has been detected as adware by 5 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named SPDriver triggered to execute each time a user logs in.
Product:
JsDriver

Version:
1,37,0,1375

MD5:
7718fc34102aa49b018ebd3e9d77af12

SHA-1:
6e9b6a1c7973494982551818f27021aaaa6f82f4

SHA-256:
a2b9942e87a1595ebf4635010fb98088e3e49d29046119801842c2f0dcb9a433

Scanner detections:
5 / 68

Status:
Adware

Analysis date:
4/18/2024 9:31:25 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.W32.Gen
2.1.4+

AhnLab V3 Security
Adware/Win32.Shopper
2014.10.20

Baidu Antivirus
Adware.Win32.ShopperPro
4.0.3.141019

ESET NOD32
Win32/ShopperPro (variant)
8.10587

Reason Heuristics
PUP.Goobzo.Task.F
14.10.19.18

File size:
3.1 MB (3,224,064 bytes)

Product version:
1,37,0,1375

Copyright:
Copyright (C) 2014

Original file name:
jsdrv.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\shopperpro\jsdriver\1.37.0.1375\jsdrv.exe

File PE Metadata
Compilation timestamp:
10/19/2014 8:11:18 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:UelTT02jKTr47cnf/3aqEt/O+k+nUMKcxyWthMTAgjnkW4CgXqoyO775uEfuObhp:RJsBnfva5ta+UMKcxyWthkD4CgXLb

Entry address:
0x1D1D80

Entry point:
8B, FF, 55, 8B, EC, E8, B6, A9, 01, 00, E8, 11, 00, 00, 00, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 6A, FE, 68, D0, 4C, 6D, 00, 68, 20, 3E, 5D, 00, 64, A1, 00, 00, 00, 00, 50, 83, C4, 98, 53, 56, 57, A1, 20, 32, 6E, 00, 31, 45, F8, 33, C5, 50, 8D, 45, F0, 64, A3, 00, 00, 00, 00, 89, 65, E8, C7, 45, 90, 00, 00, 00, 00, 8D, 45, A0, 50, FF, 15, CC, 02, 64, 00, 83, 3D, 50, 84, 6E, 00, 00, 75, 0E, 6A, 00, 6A, 00, 6A, 01, 6A, 00, FF, 15, C8, 02, 64, 00, E8, 8E, 01...
 
[+]

Code size:
2.2 MB (2,353,664 bytes)

Scheduled Task
Task name:
SPDriver

Trigger:
Logon (Runs on logon)


Remove jsdrv.exe - Powered by Reason Core Security