GbpSv.exe

Gbp Service

BANCO ITAU S/A

It runs as a separate (within the context of its own process) windows Service named “Gbp Service”.
Publisher:
BANCO ITAU S/A  (signed and verified)

Product:
Gbp Service

Description:
G-Buster Browser Defense - Service

Version:
2.4.6.0

MD5:
5f460a1fd2ba57159e10cda3cb84481a

SHA-1:
575ba81a6a60feda38918107a3af16dd80b3694f

SHA-256:
64cd9a271f5f2a1c95b92edf9cf675aebcda255bc620dcd502eb0e3e90788ca1

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/26/2024 11:42:48 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PECompact
7.1.1

Rising Antivirus
PE:PUA.XPACK-RDM!5.1
23.00.65.151227

Trend Micro House Call
TROJ_GEN.F47V1203
7.2.363

File size:
268.4 KB (274,832 bytes)

Product version:
2.4.6.0

Copyright:
Copyright © 2003-2012, G-Buster Browser Defense

Trademarks:
GbpSv

Original file name:
GbpSv.exe

File type:
Executable application (Win32 EXE)

Language:
Portuguese (Brazil)

Common path:
C:\Program Files\gbplugin\gbpsv.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/4/2012 8:00:00 PM

Valid to:
6/9/2013 7:59:59 PM

Subject:
CN=BANCO ITAU S/A, OU=DIOTI - Superintendencia de Continuidade de Negocios, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=BANCO ITAU S/A, L=Sao Paulo, S=Sao Paulo, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6A5F64A01854E848E5D9116C3FF88937

File PE Metadata
Compilation timestamp:
7/18/2012 8:56:39 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:aG72lsQyYkDHWRR0xdpt1p9UJtbaDmi+yvex9ZOruLGx0dzo:aGCaQyYkyReptCJtbKmi+yvegaLGx0d0

Entry address:
0x2C721

Entry point:
B8, 24, 2D, 4B, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, C2, 12, A0, 03, 34, 55, 87, 4A, 2C, 3B, 8E, 9E, DB, 82, D9, FB, 2C, 01, 29, 91, F7, 2C, 96, C5, 05, 7B, 32, 35, AE, FE, 3B, 8E, 78, 43, 09, 4D, 74, 76, C6, 19, D1, 24, A1, 8C, 7D, 89, 7C, 87, 5C, 95, 18, 87, 8F, C4, A0, A3, 5F, 0B, AD, CB, F9, A6, 73, 95, 33, D4, 62, F0, 75, A4, A7, 76, 31, 8F, 7B, BD, 63, E2, 91, 2E, 4D, D4, 42, C0, 91, C3, 9B, 8C, 44, 42, A1, 6C, 88...
 
[+]

Entropy:
7.9811

Packer / compiler:
PECompact v2

Code size:
495 KB (506,880 bytes)

Service
Display name:
Gbp Service

Service name:
GbpSv

Description:
Service for G-Buster Browser Defense

Type:
Win32OwnProcess

Group:
GbPlugin Group


Scan GbpSv.exe - Powered by Reason Core Security