nvkjwdrv.sys threat report

MD5 88dcce59ca53d73d0d65c152c4af5442
Latest seen 2024-05-07 23:11:30 (2 years ago)
First seen 2018-05-16 10:00:48 (7 years ago)
Size 134 KB
Publisher NVIDIA Corporation

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Agent. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Agent
Recommended action
Scan and remove
Last analysis
2024-05-07 23:11:30 (2 years ago)
File hash
88dcce59ca53d73d0d65c152c4af5442
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Agent.

Timeline

First seen 2018-05-16 10:00:48 (7 years ago); latest analysis 2024-05-07 23:11:30 (2 years ago).

Publisher context

Company metadata: NVIDIA Corporation.

Digital signature

Signed by Fuqing Yuntan Network Tech Co.,Ltd.. The signature is reported as valid, but signed files can still be bundled or abused.

Aliases

This hash has appeared under multiple file names, which can happen with repackaging, bundling, or deliberate renaming.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

nvkjwdrv.sys is a Windows file recorded in the ThreatInfo database. The reported company name is NVIDIA Corporation. The current detection status is Trojan.Agent, based on the latest analysis from 2024-05-07 23:11:30 (2 years ago).

If nvkjwdrv.sys appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Agent.

Company Name: NVIDIA Corporation
MD5: 88dcce59ca53d73d0d65c152c4af5442
Size: 134 KB
First Published: 2018-05-16 10:00:48 (7 years ago)
Latest Published: 2024-05-07 23:11:30 (2 years ago)
Status: Trojan.Agent (on last analysis)
Analysis Date: 2024-05-07 23:11:30 (2 years ago)
nvkjwdrv.sys detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

Signed By: Fuqing Yuntan Network Tech Co.,Ltd.
Status: Valid

The signature on nvkjwdrv.sys is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%system%
%system%

ThreatInfo has observed nvkjwdrv.sys in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

nvcmudrv.sys
nvwcodrv.sys
nvqmgdrv.sys
nveokdrv.sys
nvnngdrv.sys
nvpgldrv.sys
nvlhgdrv.sys
nvekmdrv.sys
nvikmdrv.sys
nvglxdrv.sys
nvolkdrv.sys
nvifcdrv.sys
nvbxpdrv.sys
nvlxwdrv.sys
nveajdrv.sys
nvdiudrv.sys
nvtkcdrv.sys
nvgyedrv.sys
nvelqdrv.sys
nvqwgdrv.sys
nvigudrv.sys
nvifjdrv.sys
nvkxmdrv.sys
nvincdrv.sys
nvbivdrv.sys
nvmfidrv.sys
nvrgndrv.sys
nvwmndrv.sys
nvijvdrv.sys
nvmusdrv.sys
nvpwvdrv.sys
nvlmldrv.sys
nvtwpdrv.sys
nvqxudrv.sys
nvudedrv.sys
nvdkgdrv.sys
nvvyvdrv.sys
nvkssdrv.sys
nvdgsdrv.sys
nvlcrdrv.sys
nvqegdrv.sys
nvpqsdrv.sys
nvsxldrv.sys
nviwcdrv.sys
nvhxadrv.sys
nvojodrv.sys
nvipmdrv.sys
nvnqldrv.sys
nvxcadrv.sys
nvuopdrv.sys
nvftkdrv.sys
nvjhldrv.sys
nvyykdrv.sys
nvtvsdrv.sys
nvnsjdrv.sys
nvlgsdrv.sys
nvbwadrv.sys
nvxnddrv.sys
nvpyedrv.sys
nvjlydrv.sys
nvfsidrv.sys
nvchcdrv.sys
nvyipdrv.sys
nvjbwdrv.sys
nvmmwdrv.sys
nvxjvdrv.sys
nvxugdrv.sys
nvbiadrv.sys
nvtbydrv.sys
nvjqmdrv.sys
nvnovdrv.sys
nvcaidrv.sys
nvioudrv.sys
nvxcmdrv.sys
nvavddrv.sys
nvcqhdrv.sys
nvhdrdrv.sys
nviikdrv.sys
nvwnwdrv.sys
nvhtbdrv.sys
nvoeddrv.sys
nvakhdrv.sys
nvtimdrv.sys
nvaicdrv.sys
nvlirdrv.sys
nvmfrdrv.sys
nvfhqdrv.sys
nvlhxdrv.sys
nvxfodrv.sys
nvpfkdrv.sys
nvkaedrv.sys
nvvpkdrv.sys
nvnqhdrv.sys
nvkundrv.sys
nvtledrv.sys
nvgitdrv.sys
nvwncdrv.sys
nvaihdrv.sys
nvdvudrv.sys
nvglsdrv.sys
nvuoudrv.sys
nvjqvdrv.sys
nvmbcdrv.sys
nvxvedrv.sys
nvkohdrv.sys
nvouhdrv.sys
nvypmdrv.sys
nvsehdrv.sys
nvpwpdrv.sys
nvgmpdrv.sys
nvfghdrv.sys
nvpeodrv.sys
nvppxdrv.sys
nvjvadrv.sys
nvguddrv.sys
nvqngdrv.sys
nvrbbdrv.sys
nvjmsdrv.sys
nvmwkdrv.sys
nvbytdrv.sys
nvvocdrv.sys
nvcfidrv.sys
nviiadrv.sys
nvwkwdrv.sys
nvsbidrv.sys
nvweddrv.sys
nvwdddrv.sys
nvjopdrv.sys
nvtapdrv.sys
nvkdvdrv.sys
nvlqmdrv.sys
nvmqhdrv.sys
nvwbedrv.sys
nvfufdrv.sys
nvxgpdrv.sys
nvogldrv.sys
nvoqgdrv.sys
nvkhadrv.sys
nvdpmdrv.sys
nvposdrv.sys
nvxhudrv.sys
nvdaadrv.sys
nvkjwdrv.sys

This hash has been seen with multiple file names. Alternate names can appear when software is updated, copied between folders, packed by an installer, or deliberately renamed to avoid recognition. Compare the exact MD5 above before assuming two names refer to the same file.

13.8%
9.5%
8.1%
7.6%
5.7%
5.2%
5.2%
5.2%
3.8%
2.9%
2.9%
2.4%
2.4%
2.4%
1.4%
1.4%
1.4%
1.4%
1.0%
1.0%
1.0%
1.0%
1.0%
1.0%
1.0%
1.0%
1.0%
1.0%
1.0%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%

The strongest geographic signal for this file is Vietnam with 13.8% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 59.2%
Windows 7 35.5%
Windows 8.1 5.2%

The most common operating system signal for nvkjwdrv.sys is Windows 10 with 59.2% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

nvkjwdrv.sys is identified as pe for 64 systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Native
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000000010000
Entry Address: 0x000320af

PE Sections:

Name Size of data MD5
.text 0 00000000000000000000000000000000
.rdata 0 00000000000000000000000000000000
.data 0 00000000000000000000000000000000
.pdata 0 00000000000000000000000000000000
INIT 0 00000000000000000000000000000000
.flk0 0 00000000000000000000000000000000
.flk1 130560 ec7b463baba0eccc994fecdb832cbe1b
.reloc 512 45755de55b27b68236def2c20a244b62
.rsrc 512 24b31c07b16b7192d2d44c2922c00800

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: