jsdrv.exe

JsDriver

The application jsdrv.exe has been detected as adware by 8 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named SPDriver triggered to execute each time a user logs in.
Product:
JsDriver

Version:
1,37,0,1389

MD5:
24b6665d5ba2564392641a51bf7fac7c

SHA-1:
9f051d000592290cf119c3a17c6ed09998f06fc0

SHA-256:
3405d7f29356a1c639f772051afe2674ac6154eebb8a0f120d5501c6509d69c9

Scanner detections:
8 / 68

Status:
Adware

Analysis date:
4/19/2024 4:17:31 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.W32.Gen
2.1.4+

AhnLab V3 Security
Adware/Win32.Shopper
2014.10.31

Baidu Antivirus
Adware.Win32.ShopperPro
4.0.3.141030

ESET NOD32
Win32/ShopperPro (variant)
8.10646

IKARUS anti.virus
PUA.ShopperPro
t3scan.1.8.3.0

K7 AntiVirus
Unwanted-Program
13.185.14120

Reason Heuristics
PUP.Goobzo.Task.F
14.10.30.17

SUPERAntiSpyware
Trojan.Agent/Gen-Goobzo
9978

File size:
3.1 MB (3,224,064 bytes)

Product version:
1,37,0,1389

Copyright:
Copyright (C) 2014

Original file name:
jsdrv.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\shopperpro\jsdriver\1.37.0.1389\jsdrv.exe

File PE Metadata
Compilation timestamp:
10/30/2014 8:10:07 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:uelTT02jKTr47cnf/3aqEt/O+k+nUMKcxyWthMTAgjnkW4CgXqoyOJ75u2UuZbhp:TJsBnfva5ta+UMKcxyWthkD4CgXTb

Entry address:
0x1D1D80

Entry point:
8B, FF, 55, 8B, EC, E8, B6, A9, 01, 00, E8, 11, 00, 00, 00, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 6A, FE, 68, D0, 4C, 6D, 00, 68, 20, 3E, 5D, 00, 64, A1, 00, 00, 00, 00, 50, 83, C4, 98, 53, 56, 57, A1, 20, 32, 6E, 00, 31, 45, F8, 33, C5, 50, 8D, 45, F0, 64, A3, 00, 00, 00, 00, 89, 65, E8, C7, 45, 90, 00, 00, 00, 00, 8D, 45, A0, 50, FF, 15, CC, 02, 64, 00, 83, 3D, 50, 84, 6E, 00, 00, 75, 0E, 6A, 00, 6A, 00, 6A, 01, 6A, 00, FF, 15, C8, 02, 64, 00, E8, 8E, 01...
 
[+]

Code size:
2.2 MB (2,353,664 bytes)

Scheduled Task
Task name:
SPDriver

Trigger:
Logon (Runs on logon)


Remove jsdrv.exe - Powered by Reason Core Security