googleupdate.exe

Yupeng Zhang

The application googleupdate.exe by Yupeng Zhang has been detected as a potentially unwanted program by 3 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Google Protect Service(gprotect)”.
Publisher:
Yupeng Zhang  (signed and verified)

Version:
47.10.2526.80

MD5:
047e10a0f52c155968050b71e5b5cf80

SHA-1:
161c1e72ae96155e3f5ad109f9ea375ba3b1a162

SHA-256:
f11c0057b00916b118e8ed466393a188415f7e8105d59ad1e155bc5c41490992

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
1/13/2025 7:13:13 PM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Gen:Variant.Adware.Ghoskwa
10.0.0.5735

F-Secure
Variant.Adware.Ghoskwa
5.15.21

Norman
Gen:Variant.Adware.Ghoskwa.1
17.02.2016 05:18:35

File size:
383.4 KB (392,576 bytes)

Product version:
47.10.2526.80

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\google\update\googleupdate.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
10/23/2015 12:00:00 AM

Valid to:
10/22/2016 11:59:59 PM

Subject:
CN=Yupeng Zhang, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
182977886EA709BC13B5E49D243C3907

File PE Metadata
Compilation timestamp:
1/12/2016 4:25:56 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:W2OPMyN8bQx5K9POc6sK4ujbD2OPMy32OPMyO:W2OZN/x52Oc6V3jbD2OZ32OZO

Entry address:
0x1E2E0

Entry point:
E8, D2, E8, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, 3C, F5, A0, 74, 44, 00, 00, 75, 13, 56, E8, 71, 00, 00, 00, 59, 85, C0, 75, 08, 6A, 11, E8, F3, 67, 00, 00, 59, FF, 34, F5, A0, 74, 44, 00, FF, 15, 04, 92, 43, 00, 5E, 5D, C3, 56, 57, BE, A0, 74, 44, 00, 8B, FE, 53, 8B, 1F, 85, DB, 74, 17, 83, 7F, 04, 01, 74, 11, 53, FF, 15, E4, 90, 43, 00, 53, E8, B1, CA, FF, FF, 83, 27, 00, 59, 83, C7, 08, 81, FF, C0, 75, 44, 00, 7C, D8, 5B, 83, 3E, 00, 74, 0E, 83, 7E, 04, 01, 75, 08, FF, 36, FF, 15...
 
[+]

Code size:
222.5 KB (227,840 bytes)

Service
Display name:
Google Protect Service(gprotect)

Service name:
gprotect

Description:
To ensure your Google software integrity. If this service is disabled or stopped, your Google software will not be kept integrity check, meaning security vulnerabilities that may arise cannot be fixed

Type:
Win32OwnProcess

Depends on:
RpcSs


Remove googleupdate.exe - Powered by Reason Core Security