SBUpdate.exe

SBUpdate Module

Speed-Bit LTD

The application SBUpdate.exe by Speed-Bit has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Speedbit Ltd.  (signed by Speed-Bit LTD)

Product:
SBUpdate Module

Version:
1, 0, 3, 4

MD5:
455e35afdfeb2ab6339c60c7e8cdf265

SHA-1:
6065d8cbcbf47342958e79ae3a75d602d3aaf4b2

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/24/2024 5:15:01 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SpeedBit.Updater (M)
17.3.15.8

File size:
264.5 KB (270,812 bytes)

Product version:
1, 0, 3, 4

Copyright:
Copyright 2012

Original file name:
SBUpdate.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\sbupdate.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/26/2012 2:00:00 AM

Valid to:
9/4/2014 1:59:59 AM

Subject:
CN=Speed-Bit LTD, OU=SECURE APPLICATION DEVELOPMENT, O=Speed-Bit LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
699AEB21842CD56CA7A7FC71BB394361

File PE Metadata
Compilation timestamp:
4/14/2013 3:07:52 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x19000

Entry point:
90, 68, BD, F9, F1, 00, 5B, 90, 68, 22, 90, 41, 00, 5A, 90, 90, 68, 98, 05, 00, 00, 5F, 90, 31, 1C, 3A, 90, 83, EF, 03, 4F, 90, 90, 75, F4, 90, 90, 90, 55, 84, F0, 00, BD, F9, F1, 00, BD, F9, B1, 00, 1F, A9, F1, 00, 3D, 93, F0, 00, 61, 88, F0, 00, BD, 49, F3, 00, BC, F9, F1, 00, 99, 09, B1, 00, 0B, E6, B0, 00, 7F, E6, B0, 00, E5, E8, F0, 00, 09, E6, F0, 00, 7D, E6, F0, 00, 99, 1D, F1, 00, 09, E6, F0, 00, 7D, E6, F0, 00, BD, F9, F1, 00, BD, F9, F1, 00, BD, F9, F1, 00, BD, F9, F1, 00, CD, 09, B1, 00, BD, F9...
 
[+]

Entropy:
7.6392

Code size:
56 KB (57,344 bytes)

Remove SBUpdate.exe - Powered by Reason Core Security