fbdownloaderupdate.exe

HTTO GROUP Ltd

The application fbdownloaderupdate.exe by HTTO GROUP has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “FBDownloader Update Service”.
Publisher:
HTTO GROUP Ltd  (signed and verified)

MD5:
41954228c24ea6e1dfb64c8494aa3f7b

SHA-1:
71d160ed6b091a5a34ec628b778721ceab795b07

SHA-256:
23f77dc318a091db79f6346206675a49eb4fc5234255e497f8b52aa2eb8dd647

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
7/6/2025 3:14:06 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.9.14

File size:
18.1 KB (18,544 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\fbdownloader\fbdownloaderupdate.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
6/7/2012 3:34:46 PM

Valid to:
6/8/2013 3:34:46 PM

Subject:
CN=HTTO GROUP Ltd, O=HTTO GROUP Ltd, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11215406F83784DB7388225378818F7FF3A2

File PE Metadata
Compilation timestamp:
7/22/2012 12:01:14 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

Entry address:
0x29F0

Entry point:
55, 8B, EC, 83, EC, 18, 8D, 45, FC, 50, FF, 15, 38, 30, 40, 00, 50, FF, 15, B8, 30, 40, 00, 89, 45, F8, 83, 7D, F8, 00, 0F, 84, 88, 00, 00, 00, 83, 7D, FC, 01, 7E, 78, 8B, 4D, F8, 8B, 51, 04, 52, FF, 15, 74, 30, 40, 00, 8D, 44, 00, 02, 50, 6A, 40, FF, 15, 84, 30, 40, 00, A3, 38, 40, 40, 00, 83, 3D, 38, 40, 40, 00, 00, 74, 50, 8B, 4D, F8, 8B, 51, 04, 52, A1, 38, 40, 40, 00, 50, FF, 15, AC, 30, 40, 00, E8, 06, FF, FF, FF, 85, C0, 74, 28, 8B, 0D, 38, 40, 40, 00, 89, 4D, E8, C7, 45, EC, A0, 27, 40, 00, C7, 45...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
7 KB (7,168 bytes)

Service
Display name:
FBDownloader Update Service

Service name:
FBDownloaderUpdate

Type:
Win32OwnProcess


Remove fbdownloaderupdate.exe - Powered by Reason Core Security