FBSWorker.exe

Ferro Backup System

Ferro Software

Publisher:
Ferro Software  (signed and verified)

Product:
Ferro Backup System

Description:
Ferro Backup System - Worker

Version:
4.1.2.1031

MD5:
6113b704652c195c243c0161f86b0ba7

SHA-1:
25f4ef009b752b52a2882db3e4c86facad5a0077

SHA-256:
eb848c065239e16fb3034ef10091f7b200a5156144f099f9d3073745a85f6fc6

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/27/2024 7:51:12 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
probably BACKDOOR.Trojan
9.0.1.05190

File size:
472.4 KB (483,712 bytes)

Product version:
3

Copyright:
FERRO Software

Trademarks:
FERRO Software

Original file name:
FBSWorker.exe

File type:
Executable application (Win32 EXE)

Language:
Polish

Common path:
C:\Program Files\ferro software\ferro backup system\fbsworker.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
4/25/2013 7:16:46 AM

Valid to:
4/25/2014 7:16:46 AM

Subject:
E=ferro@ferro.com.pl, CN=Ferro Software, O=Ferro Software, C=PL

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
4AD0F5292F7286B21377CC2084968CCA

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:RRugb999+8sW5AVH1fMW8P/X5f3rOqnuX0JvkJswK:RpNqW5AVH1x8P/JjO+uXuMywK

Entry address:
0x5AE64

Entry point:
55, 8B, EC, 81, C4, C4, FE, FF, FF, 53, 56, 57, 33, C0, 89, 45, C8, 89, 45, C4, 89, 45, CC, 89, 45, D8, 89, 45, E4, 89, 45, DC, 89, 45, E0, 89, 45, EC, 89, 45, E8, B8, 34, AB, 45, 00, E8, 25, BD, FA, FF, 33, C0, 55, 68, 6A, B2, 45, 00, 64, FF, 30, 64, 89, 20, 33, C0, 55, 68, 97, B1, 45, 00, 64, FF, 30, 64, 89, 20, 6A, 00, E8, C6, C1, FA, FF, 83, C8, 01, 50, E8, BD, C1, FA, FF, 8D, 55, E8, 33, C0, E8, 93, 83, FA, FF, 8B, 45, E8, 8D, 55, EC, E8, D4, 08, FB, FF, 8B, 45, EC, E8, 74, 0E, FB, FF, 8D, 45, E4, 50...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
361.5 KB (370,176 bytes)

Scan FBSWorker.exe - Powered by Reason Core Security