fbvdupdate7.2.exe

VIDEO TECH PRODUCOES LTDA - ME

The application fbvdupdate7.2.exe by VIDEO TECH PRODUCOESA - ME has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
VIDEO TECH PRODUCOES LTDA - ME  (signed and verified)

MD5:
fa2364ed7dfa94bddc6456d5a182aee9

SHA-1:
5834fc480ba93e4b1471d0dabcd34699f6428fa5

SHA-256:
1d946e51819cfd30427b78711e60a210f4f5eddfe11d9c5f17542068c55dae1c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 4:54:26 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.VIDEOTECHPRODUCOESAME (M)
16.2.14.15

File size:
1.4 MB (1,426,728 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\fbvdupdate7.2.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/1/2013 9:00:00 PM

Valid to:
7/2/2014 8:59:59 PM

Subject:
CN=VIDEO TECH PRODUCOES LTDA - ME, O=VIDEO TECH PRODUCOES LTDA - ME, L=Florianópolis, S=Santa Catarina, C=BR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
75BF24911D0DEAA1302738F5948159B1

File PE Metadata
Compilation timestamp:
10/25/2013 12:02:50 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:iOHgaa8wEXTTTUvZcTeqDynwYPaaob3O4+HtwzTOUpylECQDaSAe8VxGP4:lVvbTX+wYxob+4e+zTOUMECQme8VxGP4

Entry address:
0x25A000

Entry point:
EB, 03, BB, A7, 76, 50, EB, 03, 05, BC, 2C, E8, 14, 00, 00, 00, EB, 02, 63, 92, EB, 05, C5, AF, 5B, 37, 8F, 33, C0, 70, 22, 71, 6C, EB, 01, 28, EB, 05, 9A, 07, EE, 60, 03, B8, 21, 48, 9B, F6, EB, 03, 0D, 57, 88, EB, 05, 9A, 2E, 6E, 6C, C4, 05, DF, B7, 64, 09, EB, 02, 31, 58, 75, 46, EB, 03, 69, E6, 47, 64, FF, 30, EB, 05, 6B, 93, FB, 21, E1, 64, 89, 20, EB, 04, 9A, EE, DC, D2, EB, 04, 15, 35, FD, EF, 8B, 10, EB, 04, 8B, 87, AA, 63, 64, 8F, 00, EB, 05, 21, 05, 20, F9, DD, 83, C4, 04, EB, 05, 86, BD, 91, 43...
 
[+]

Code size:
110 KB (112,640 bytes)

Remove fbvdupdate7.2.exe - Powered by Reason Core Security