sendori32.sys

Sendori Watchdog

Sendori, Inc

This is part of the Sendori web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The file sendori32.sys by Sendori, Inc has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Sendori  (signed by Sendori, Inc)

Product:
Sendori Watchdog

Description:
Watchdog Driver

Version:
2.2.1.5

MD5:
2f35fc993d4197075c438c9e2324a0b3

SHA-1:
725071c9981b2db53538ba2a79722c2042f2abce

SHA-256:
a051ef0b0bb1825ee4e1812187fea2a869f5b3545fe8556dd52b6b9e4f3ae659

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/16/2024 11:39:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sendori (M)
15.12.25.20

File size:
25.7 KB (26,272 bytes)

Product version:
2.2.1.5

Copyright:
© Sendori. All rights reserved.

Original file name:
sendori32.sys

File type:
Driver (Win32 SYS)

Language:
Language Neutral

Common path:
C:\Program Files\sendori\sendori32.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/10/2013 5:00:00 PM

Valid to:
5/10/2014 4:59:59 PM

Subject:
CN="Sendori, Inc", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Sendori, Inc", L=Oakland, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7442E44B0C8A4CAFD2E5797F9201E3FF

File PE Metadata
Compilation timestamp:
10/8/2012 4:40:45 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
384:mQGEjquIX1DzwXjoLztZNQmWJ4EuXcOKTy+bvKvex6gjGyRTdd6lHhnYPLYOeME:B6XdfQ4VXcOn+bSvFAT/uHh5

Entry address:
0x40A6

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 50, FF, FF, FF, CC, CC, E0, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, D2, 45, 00, 00, 80, 3B, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B8, 41, 00, 00, D2, 41, 00, 00, E4, 41, 00, 00, FC, 41, 00, 00, 0C, 42, 00, 00, 24, 42, 00, 00, 36, 42, 00, 00, 40, 42, 00, 00, 4A, 42, 00, 00, 62, 42, 00, 00, 70, 42, 00, 00, 84, 42, 00, 00, 9C, 42, 00, 00, A6, 42, 00, 00, BA, 42, 00, 00, DA, 42, 00, 00, EE, 42, 00, 00, 06, 43...
 
[+]

Entropy:
6.7818

Code size:
15.3 KB (15,616 bytes)

Remove sendori32.sys - Powered by Reason Core Security