jsdrv.exe

JsDriver

Goobzo LTD

The application jsdrv.exe by Goobzo has been detected as adware by 7 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named SPDriver triggered to execute each time a user logs in.
Publisher:
Goobzo LTD  (signed and verified)

Product:
JsDriver

Version:
1.0.0.21

MD5:
b83442678e25c717beb0b8d76a781edf

SHA-1:
c22aabfc56e5f5dd9824503b095697c11b07d767

SHA-256:
218e84ac9ec2962d30744d318cd2b92100bbafee2eff139dc61bbf7ad049f339

Scanner detections:
7 / 68

Status:
Adware

Analysis date:
12/20/2025 1:13:57 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Crypt.XPACK.Gen
7.11.132.140

AVG
MalSign.Skodna
2015.0.3556

Comodo Security
UnclassifiedMalware
17810

McAfee
Artemis!B83442678E25
5600.7212

Reason Heuristics
PUP.Goobzo.Task.F
14.8.8.2

Trend Micro House Call
TROJ_GEN.F47V0215
7.2.53

VIPRE Antivirus
Goobzo
26612

File size:
3.1 MB (3,208,552 bytes)

Product version:
1,0,0,21

Copyright:
Copyright (C) 2014

Original file name:
jsdrv.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\shopperpro\jsdriver\1.0.0.21\jsdrv.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/2/2013 12:00:00 AM

Valid to:
5/2/2015 11:59:59 PM

Subject:
CN=Goobzo LTD, O=Goobzo LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
120B25DDE57B88636AD4D97D23B99C88

File PE Metadata
Compilation timestamp:
2/13/2014 3:50:04 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:qd3EksF/KcQ77/aoNExTIKYMSJRENdTFOf2y4R:qd3Js9A/a+EFIKlsfA

Entry address:
0x1ABA60

Entry point:
55, 8B, EC, E8, F8, E9, 01, 00, E8, 03, 00, 00, 00, 5D, C3, CC, 55, 8B, EC, 6A, FE, 68, 78, 92, 69, 00, 68, 40, E8, 5A, 00, 64, A1, 00, 00, 00, 00, 50, 83, C4, E0, 53, 56, 57, A1, C0, 70, 6A, 00, 31, 45, F8, 33, C5, 50, 8D, 45, F0, 64, A3, 00, 00, 00, 00, 89, 65, E8, C7, 45, E0, 00, 00, 00, 00, E8, 91, 3E, 01, 00, 66, 89, 45, E4, 6A, 02, E8, D6, E8, 01, 00, 83, C4, 04, E8, 3E, 01, 00, 00, 89, 45, D4, E8, 86, 63, 01, 00, 85, C0, 75, 0A, 6A, 1C, E8, BB, 01, 00, 00, 83, C4, 04, E8, 73, 61, 01, 00, 85, C0, 75...
 
[+]

Code size:
2.1 MB (2,168,320 bytes)

Scheduled Task
Task name:
SPDriver

Trigger:
Logon (Runs on logon)


Remove jsdrv.exe - Powered by Reason Core Security