GbpSv.exe

Gbp Service

BANCO ITAU S/A

It runs as a separate (within the context of its own process) windows Service named “Gbp Service”.
Publisher:
BANCO ITAU S/A  (signed and verified)

Product:
Gbp Service

Description:
G-Buster Browser Defense - Service

Version:
2.4.3.0

MD5:
41e6c88d2baad58b28b73b8c81ed72b3

SHA-1:
61571e9a3e8510aaab6f4ec91804353f4c0cf6af

SHA-256:
91c58bdef47a189764f7c74cc9557c664da2cd1ca00d1a50a7f3707fb779607b

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/23/2024 11:20:15 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Rising Antivirus
PE:PUA.XPACK-RDM!5.1
23.00.65.16128

Trend Micro House Call
TROJ_GEN.F47V1203
7.2.30

File size:
199.7 KB (204,480 bytes)

Product version:
2.4.3.0

Copyright:
Copyright © 2003-2011, G-Buster Browser Defense

Trademarks:
GbpSv

Original file name:
GbpSv.exe

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\Program Files\gbplugin\gbpsv.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/4/2012 9:00:00 PM

Valid to:
6/9/2013 8:59:59 PM

Subject:
CN=BANCO ITAU S/A, OU=DIOTI - Superintendencia de Continuidade de Negocios, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=BANCO ITAU S/A, L=Sao Paulo, S=Sao Paulo, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6A5F64A01854E848E5D9116C3FF88937

File PE Metadata
Compilation timestamp:
12/13/2011 7:35:48 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:QGP+e0Yn4vkgpg5DMtcFf7scOIRn4eoxg4lQ4VbQ9X1uKCdgxGnNCYbqfHUmT7R5:QGP+1Ykw7oxV5u0dMGnhbnwnNuo

Entry address:
0x25300

Entry point:
B8, 4C, 7D, 48, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 0C, 91, 3D, 3A, 11, 70, 42, 93, 6E, 01, 78, E8, E1, BC, 88, 83, 40, 4C, B1, C7, B7, 66, 54, 36, 1C, B2, 5E, FA, 17, 9F, 95, AF, DC, C1, 37, 6E, 08, AC, 51, 06, E3, CD, 45, E0, 8E, E1, 43, EF, 6C, 5B, 1A, C4, B4, CB, E2, CD, A0, 45, A7, 21, 6B, 79, D7, 12, 43, E0, FA, 48, 87, B0, 30, 04, B4, 9B, CD, 0A, B3, DB, 9E, 87, 58, 49, D3, A7, 20, D6, C2, BE, B9, 99, C4, 32, 91...
 
[+]

Packer / compiler:
PECompact v2

Code size:
358.5 KB (367,104 bytes)

Service
Display name:
Gbp Service

Service name:
GbpSv

Description:
Service for G-Buster Browser Defense

Type:
Win32OwnProcess

Group:
GbPlugin Group


Scan GbpSv.exe - Powered by Reason Core Security