GoogleUpdaterService.exe

Google Updater

Google

The executable GoogleUpdaterService.exe has been detected as malware by 38 anti-virus scanners. It runs as a separate (within the context of its own process) windows Service named “Google Software Updater”. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
Publisher:
Google

Product:
Google Updater

Description:
gusvc

Version:
2.4.2617.4952.beta

MD5:
0d6f91ecbf80f75055c44851f9f43fed

SHA-1:
5535b0fe2d5355cff26becd297218e012d87243c

SHA-256:
2e3fa24e2e5a3da7320b717352d8437856f4f585a6d27a16a1ebb7e4ef8702ab

Scanner detections:
38 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/24/2024 10:57:13 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
856

AegisLab AV Signature
W32.Sality
2.1.4+

Agnitum Outpost
Win32.Sality.AP.Gen
7.1.1

AhnLab V3 Security
Win32/Kashu.E
2014.10.02

Avira AntiVirus
W32/Sality.AG
7.11.30.172

avast!
Win32:Kukacka
140929-0

AVG
Win32/Sality
2014.0.4025

Baidu Antivirus
Virus.Win32.Sality.$Emu
4.0.3.14102

Bitdefender
Win32.Sality.3
1.0.20.1375

Bkav FE
W32.Sality.PE
1.3.0.4959

Comodo Security
Virus.Win32.Sality.Gen
19681

Dr.Web
Win32.Sector.21
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
14.10.02

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
11.2014-02-10_5

G Data
Win32.Sality
14.10.24

IKARUS anti.virus
Virus.Win32.Sality
t3scan.1.7.8.0

K7 AntiVirus
Virus
13.183.13550

Kaspersky
Virus.Win32.Sality
15.0.0.494

McAfee
W32/Sality.gen.z
5600.6990

Microsoft Security Essentials
Threat.Undefined
1.185.1828.0

MicroWorld eScan
Win32.Sality.3
15.0.0.825

NANO AntiVirus
Virus.Win32.Sality.yusp
0.28.2.62440

Norman
Sality.ZHB
11.20141002

nProtect
Virus/W32.Sality.D
14.10.02.01

Panda Antivirus
W32/Sality.AA
14.10.02.08

Qihoo 360 Security
Malware.QVM19.Gen
1.0.0.1015

Quick Heal
W32.Sality.U
10.14.14.00

Rising Antivirus
PE:Win32.KUKU.kt!1591113
23.00.65.14930

Sophos
Mal/Sality-D
4.98

Total Defense
Win32/Sality.AA
37.0.11209

Trend Micro House Call
PE_SALITY.RL
7.2.275

Trend Micro
PE_SALITY.RL
10.465.02

Vba32 AntiVirus
Virus.Win32.Sality.bakb
3.12.26.3

VIPRE Antivirus
Threat.4721115
33120

ViRobot
Win32.Sality.N
2011.4.7.4223

Zillya! Antivirus
Virus.Sality.Win32.20
2.0.0.1940

File size:
252 KB (258,048 bytes)

Product version:
2.4.2617.4952.beta

Copyright:
©2005-2006 Google. All Rights Reserved.

Original file name:
GoogleUpdaterService.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\google\common\google updater\googleupdaterservice.exe

File PE Metadata
Compilation timestamp:
3/2/2012 1:13:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:0M6TZq22uAebpeo5u00SZ1aa956wtwOsJsukqSr:h6T+uAe8oM6ZUajrsmuDU

Entry address:
0x11E48

Entry point:
60, 0F, BE, D9, 69, F3, E0, 96, 62, D0, 85, C2, 68, 29, 3B, 7A, 00, 0F, BF, F5, 85, F8, B0, C5, FE, C7, F2, BB, 89, F5, DA, C5, 3B, CE, 86, FB, FE, C6, 25, B8, 3C, C6, 00, C6, C3, 84, 89, D9, 8D, 2D, AB, 20, FE, 5A, 24, C4, E8, 1F, 00, 00, 00, 69, F3, D8, 97, A5, 8D, F3, 8D, 35, 16, CB, 28, 89, 86, F5, BE, B7, 12, 08, E7, 85, FE, 85, E9, B3, 44, 3D, E0, 9D, 00, 00, FE, CE, FE, CC, 8A, DE, 8B, C0, 84, E1, F3, 68, C8, 64, 00, 00, 8D, 05, 5E, 15, 7B, 31, 59, 84, E7, 34, 9E, 0D, 40, 05, 77, C7, 81, F1, CA, 07...
 
[+]

Entropy:
6.9768

Code size:
125 KB (128,000 bytes)

Service
Display name:
Google Software Updater

Service name:
gusvc

Description:
Google Updater keeps your Google software up to date. If Google Updater Service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may aris

Type:
Win32OwnProcess

Depends on:
RPCSS


Remove GoogleUpdaterService.exe - Powered by Reason Core Security