sendori32.sys

Sendori Watchdog

Sendori, Inc

This is part of the Sendori web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The file sendori32.sys by Sendori, Inc has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Sendori  (signed by Sendori, Inc)

Product:
Sendori Watchdog

Description:
Watchdog Driver

Version:
2.2.1.5

MD5:
e0b263b65fdf81ad4c86fad182dfd4a5

SHA-1:
b7dc23e2b3a295522e061a9ebafd6c6d0d27c27a

SHA-256:
16428daf1df86afc348214e6e510c70504fc13a8c75f6282b80157d1fb1b89af

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/20/2024 4:14:36 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sendori (M)
16.1.4.13

File size:
25.7 KB (26,272 bytes)

Product version:
2.2.1.5

Copyright:
© Sendori. All rights reserved.

Original file name:
sendori32.sys

File type:
Driver (Win32 SYS)

Language:
Language Neutral

Common path:
C:\Program Files\sendori\sendori32.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/10/2013 5:00:00 PM

Valid to:
5/10/2014 4:59:59 PM

Subject:
CN="Sendori, Inc", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Sendori, Inc", L=Oakland, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7442E44B0C8A4CAFD2E5797F9201E3FF

File PE Metadata
Compilation timestamp:
10/8/2012 4:40:45 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
384:MQGEjquIX1DzwXjoLztZNQmWJ4EuXcOKTy+bvKvex6gjGyRTdd6lHhnYPLYOeM6h:P6XdfQ4VXcOn+bSvFAT/uHh3fNH

Entry address:
0x40A6

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 50, FF, FF, FF, CC, CC, E0, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, D2, 45, 00, 00, 80, 3B, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B8, 41, 00, 00, D2, 41, 00, 00, E4, 41, 00, 00, FC, 41, 00, 00, 0C, 42, 00, 00, 24, 42, 00, 00, 36, 42, 00, 00, 40, 42, 00, 00, 4A, 42, 00, 00, 62, 42, 00, 00, 70, 42, 00, 00, 84, 42, 00, 00, 9C, 42, 00, 00, A6, 42, 00, 00, BA, 42, 00, 00, DA, 42, 00, 00, EE, 42, 00, 00, 06, 43...
 
[+]

Entropy:
6.7801

Code size:
15.3 KB (15,616 bytes)

Remove sendori32.sys - Powered by Reason Core Security