fbdsf200.exe

HTTO GROUP Ltd

The application fbdsf200.exe by HTTO GROUP has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “FBDSF200”.
Publisher:
HTTO GROUP Ltd  (signed and verified)

MD5:
ce5bd2d641a0b58246609d6c2a1eacaa

SHA-1:
53ca4a271ecb6143ef1f4bef96ad6a0944122a23

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 9:10:54 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.12.12.16

File size:
18.6 KB (19,056 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\fbdownloader\fbdsf200.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
6/7/2012 9:34:46 AM

Valid to:
6/8/2013 9:34:46 AM

Subject:
CN=HTTO GROUP Ltd, O=HTTO GROUP Ltd, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11215406F83784DB7388225378818F7FF3A2

File PE Metadata
Compilation timestamp:
9/1/2012 12:36:13 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

Entry address:
0x29F0

Entry point:
55, 8B, EC, 83, EC, 18, 8D, 45, FC, 50, FF, 15, 38, 30, 40, 00, 50, FF, 15, B8, 30, 40, 00, 89, 45, F8, 83, 7D, F8, 00, 0F, 84, 88, 00, 00, 00, 83, 7D, FC, 01, 7E, 78, 8B, 4D, F8, 8B, 51, 04, 52, FF, 15, 74, 30, 40, 00, 8D, 44, 00, 02, 50, 6A, 40, FF, 15, 84, 30, 40, 00, A3, 38, 50, 40, 00, 83, 3D, 38, 50, 40, 00, 00, 74, 50, 8B, 4D, F8, 8B, 51, 04, 52, A1, 38, 50, 40, 00, 50, FF, 15, AC, 30, 40, 00, E8, 06, FF, FF, FF, 85, C0, 74, 28, 8B, 0D, 38, 50, 40, 00, 89, 4D, E8, C7, 45, EC, A0, 27, 40, 00, C7, 45...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
7 KB (7,168 bytes)

Service
Display name:
FBDSF200

Type:
Win32OwnProcess


Remove fbdsf200.exe - Powered by Reason Core Security