GloboFleet_CC_Plus.exe

GloboFleet CC Plus

Buyond GmbH

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘GloboFleet’. This is installed with GloboFleet CC Plus.
Publisher:
Buyond GmbH  (signed and verified)

Product:
GloboFleet CC Plus

Version:
2.7.1

MD5:
c50d1dc0f644479b1ed80c458e42cd0f

SHA-1:
7b4d356452819d3be090b8500118cabe4ca08ad1

SHA-256:
2ccbc133a942b076db7c349ac25c3c6aa424ebcb1363d28d1a893a6122903a84

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 6:53:39 AM UTC  (today)

File size:
332.6 KB (340,544 bytes)

Product version:
2.7.1

Copyright:
Copyright (C) Buyond GmbH

Original file name:
GloboFleet_CC_Plus.exe

File type:
Executable application (Win64 EXE)

Language:
Spanish

Common path:
C:\Program Files\buyond gmbh\globofleet cc plus\globofleet_cc_plus.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/31/2011 1:00:00 AM

Valid to:
11/2/2012 12:59:59 AM

Subject:
CN=Buyond GmbH, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Buyond GmbH, L=Kiel, S=Schleswig-Holstein, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
52BCE8469AD371D1608ED046464194CA

File PE Metadata
Compilation timestamp:
8/29/2008 1:32:51 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:0cfiNjj1MLv5mojRw2LEVE/LCD/22222hm0o:Vm5iv5LVwuER

Entry address:
0x13A88

Entry point:
48, 83, EC, 28, E8, 7B, 4A, 00, 00, 48, 83, C4, 28, E9, 12, FE, FF, FF, CC, CC, 48, 8B, C4, 48, 89, 58, 08, 48, 89, 68, 18, 48, 89, 70, 20, 48, 89, 50, 10, 57, 41, 54, 41, 55, 41, 56, 41, 57, 48, 83, EC, 40, 4D, 8B, 79, 08, 4D, 8B, 21, 49, 8B, 71, 38, 4D, 2B, E7, F6, 41, 04, 66, 4D, 8B, F1, 48, 8B, EA, 4C, 8B, E9, 0F, 85, DC, 00, 00, 00, 33, FF, 48, 89, 48, C8, 4C, 89, 40, D0, 39, 3E, 0F, 86, 2B, 01, 00, 00, 48, 8D, 5E, 0C, 8B, 43, F8, 4C, 3B, E0, 0F, 82, A7, 00, 00, 00, 8B, 43, FC, 4C, 3B, E0, 0F, 83, 9B...
 
[+]

Code size:
126 KB (129,024 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
GloboFleet

Command:
"C:\Program Files\buyond gmbh\globofleet cc plus\globofleet_cc_plus.exe" systemboot


The file GloboFleet_CC_Plus.exe has been discovered within the following program.

GloboFleet CC Plus  by Buyond GmbH
www.globofleet.com
About 4% of users remove it
 
Powered by Should I Remove It?

Scan GloboFleet_CC_Plus.exe - Powered by Reason Core Security