jsdrv.exe

JsDriver

The application jsdrv.exe has been detected as adware by 6 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named SPDriver triggered to execute each time a user logs in.
Product:
JsDriver

Version:
1,37,0,1390

MD5:
44fba4227f4f072dbf17e330e8de97b9

SHA-1:
aab8104bce4151f2ba1334bb2601cbb3901e1843

SHA-256:
b33aeeba7d98573fec1988b70ceb23fdec24566adba561bd8b7b08a566d22f08

Scanner detections:
6 / 68

Status:
Adware

Analysis date:
4/26/2024 12:24:01 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.W32.Gen
2.1.4+

AhnLab V3 Security
Adware/Win32.Shopper
2014.11.01

Baidu Antivirus
Adware.Win32.ShopperPro
4.0.3.14111

ESET NOD32
Win32/ShopperPro (variant)
8.10653

IKARUS anti.virus
PUA.ShopperPro
t3scan.1.8.3.0

Reason Heuristics
PUP.Goobzo.Task.F
14.10.31.19

File size:
3.1 MB (3,224,064 bytes)

Product version:
1,37,0,1390

Copyright:
Copyright (C) 2014

Original file name:
jsdrv.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\shopperpro\jsdriver\1.37.0.1390\jsdrv.exe

File PE Metadata
Compilation timestamp:
11/1/2014 4:10:07 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:OelTT02jKTr47cnf/3aqEt/O+k+nUMKcxyWthMTAgjnkW4CgXqoyOA75u8Euzbhp:zJsBnfva5ta+UMKcxyWthkD4CgXSb

Entry address:
0x1D1D80

Entry point:
8B, FF, 55, 8B, EC, E8, B6, A9, 01, 00, E8, 11, 00, 00, 00, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 6A, FE, 68, D0, 4C, 6D, 00, 68, 20, 3E, 5D, 00, 64, A1, 00, 00, 00, 00, 50, 83, C4, 98, 53, 56, 57, A1, 20, 32, 6E, 00, 31, 45, F8, 33, C5, 50, 8D, 45, F0, 64, A3, 00, 00, 00, 00, 89, 65, E8, C7, 45, 90, 00, 00, 00, 00, 8D, 45, A0, 50, FF, 15, CC, 02, 64, 00, 83, 3D, 50, 84, 6E, 00, 00, 75, 0E, 6A, 00, 6A, 00, 6A, 01, 6A, 00, FF, 15, C8, 02, 64, 00, E8, 8E, 01...
 
[+]

Entropy:
6.4356

Code size:
2.2 MB (2,353,664 bytes)

Scheduled Task
Task name:
SPDriver

Trigger:
Logon (Runs on logon)


Remove jsdrv.exe - Powered by Reason Core Security