googleupdate.exe

Yupeng Zhang

The application googleupdate.exe by Yupeng Zhang has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Google Protect Service(gprotect)”.
Publisher:
Yupeng Zhang  (signed and verified)

Version:
47.10.2526.80

MD5:
cfdf5b72720bbfb003751bd8c7fe2dd4

SHA-1:
b35d7abff6d41504d1c04a8161a7b87ada1c8afa

SHA-256:
f24cb4d6dba3b0ec0b12b47d33227415a507da368b97bdd947e8608767155026

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
1/13/2025 7:16:41 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Zhang.YupengZh.Meta (M)
16.7.1.16

File size:
303.2 KB (310,488 bytes)

Product version:
47.10.2526.80

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\google\update\googleupdate.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
10/22/2015 7:00:00 PM

Valid to:
10/22/2016 6:59:59 PM

Subject:
CN=Yupeng Zhang, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
182977886EA709BC13B5E49D243C3907

File PE Metadata
Compilation timestamp:
1/12/2016 9:36:01 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
3072:6U68OPMnyrVtN8bu9BwdaOwXwj8plyL1Yl5s9AVwryYYw+P2MZC2ri8PaTvn8Rgj:62OPMyN8bQx5K9POwGei4ujCr

Entry address:
0x1E2E0

Entry point:
E8, D2, E8, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, 3C, F5, A0, 74, 44, 00, 00, 75, 13, 56, E8, 71, 00, 00, 00, 59, 85, C0, 75, 08, 6A, 11, E8, F3, 67, 00, 00, 59, FF, 34, F5, A0, 74, 44, 00, FF, 15, 04, 92, 43, 00, 5E, 5D, C3, 56, 57, BE, A0, 74, 44, 00, 8B, FE, 53, 8B, 1F, 85, DB, 74, 17, 83, 7F, 04, 01, 74, 11, 53, FF, 15, E4, 90, 43, 00, 53, E8, B1, CA, FF, FF, 83, 27, 00, 59, 83, C7, 08, 81, FF, C0, 75, 44, 00, 7C, D8, 5B, 83, 3E, 00, 74, 0E, 83, 7E, 04, 01, 75, 08, FF, 36, FF, 15...
 
[+]

Code size:
222.5 KB (227,840 bytes)

Service
Display name:
Google Protect Service(gprotect)

Service name:
gprotect

Description:
To ensure your Google software integrity. If this service is disabled or stopped, your Google software will not be kept integrity check, meaning security vulnerabilities that may arise cannot be fixed

Type:
Win32OwnProcess

Depends on:
RpcSs


Remove googleupdate.exe - Powered by Reason Core Security