nvupdate.exe

The application nvupdate.exe has been detected as a potentially unwanted program by 34 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “NVIDIA Update Server”.
MD5:
8f404dec95f3f1d59e0e0d7023fb49f7

SHA-1:
4875af1d4a7b1d017691259dbcc01480b4721248

SHA-256:
e61f3586cf4e98d403b702c8cb4ebfd56824c5a35f45579a6d1fe6434b1e73e2

Scanner detections:
34 / 68

Status:
Potentially unwanted

Analysis date:
5/9/2025 2:26:24 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Agent.BCFU
1051

AhnLab V3 Security
Spyware/Win32.Zbot
14.03.20

Avira AntiVirus
TR/Carberp.A.50
7.11.138.28

avast!
Win32:Zbot-TBI [Drp]
2014.9-140320

AVG
Generic35
2015.0.3529

Baidu Antivirus
Trojan.Win32.Rovnix
4.0.3.141216

Bitdefender
Trojan.Agent.BCFU
1.0.20.395

Bkav FE
HW32.Nonim
1.3.0.4959

Comodo Security
UnclassifiedMalware
19634

Dr.Web
BackDoor.Andromeda.288
9.0.1.079

Emsisoft Anti-Malware
Trojan.Agent.BCFU
8.14.03.20.10

ESET NOD32
Win32/Injector.BAED (variant)
8.9568

Fortinet FortiGate
W32/Kryptik.WIF!tr
12/16/2014

F-Secure
Trojan.Agent.BCFU
11.2014-20-03_5

G Data
Trojan.Agent.BCFU
14.3.24

IKARUS anti.virus
Trojan.Inject2
t3scan.1.7.8.0

K7 AntiVirus
Unwanted-Program
13.183.13504

Kaspersky
Trojan.Win32.Inject
14.0.0.4140

Malwarebytes
Trojan.Agent.ED
v2014.03.20.10

McAfee
Generic-FAUT!578D062DD2AD
5600.6914

Microsoft Security Essentials
TrojanDropper:Win32/Rovnix
1.11005

MicroWorld eScan
Trojan.Agent.BCFU
15.0.0.237

NANO AntiVirus
Trojan.Win32.Xpack.cxbbsk
0.28.2.62286

Norman
Troj_Generic.TRFMA
11.20141216

nProtect
Trojan.Generic.11229991
14.09.26.01

Panda Antivirus
Trj/CI.A
14.03.20.10

Qihoo 360 Security
HEUR/Malware.QVM19.Gen
1.0.0.1015

Quick Heal
TrojanRansom.PornoAsset.r4
12.14.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
14.12.16.12

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_SPNR.0BDS14
7.2.350

Trend Micro
TROJ_SPNR.0BDS14
10.465.16

Vba32 AntiVirus
TrojanPSW.Tepfer
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
33478

File size:
64 KB (65,536 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\nvidia corporation\update center\nvupdate.exe

File PE Metadata
Compilation timestamp:
3/18/2014 2:35:10 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:Aw9lTAko92IxEXQ+4vf+bwVN0H1gb2W28:JrAky2Ixa4vDG1g+8

Entry address:
0x267E

Entry point:
55, 8B, EC, 6A, FF, 68, 78, 37, 40, 00, 68, 98, 28, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 90, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, 5F, 57, FF, 15, 34, 32, 40, 00, 59, 83, 0D, A0, 5C, 40, 00, FF, 83, 0D, A4, 5C, 40, 00, FF, FF, 15, 30, 32, 40, 00, 8B, 0D, 94, 5C, 40, 00, 89, 08, FF, 15, 2C, 32, 40, 00, 8B, 0D, 90, 5C, 40, 00, 89, 08, A1, 28, 32, 40, 00, 8B, 00, A3, 9C, 5C, 40, 00, E8, A8, 01, 00, 00, 39, 1D, 50, 50, 40, 00, 75, 0C, 68, 94, 28, 40, 00, FF, 15...
 
[+]

Entropy:
6.6685

Developed / compiled with:
Microsoft Visual C++

Code size:
8 KB (8,192 bytes)

Service
Display name:
NVIDIA Update Server

Service name:
NvUpdSrv

Description:
NVIDIA Settings Update Manager service, used to check new updates from NVIDIA server

Type:
Win32OwnProcess


Remove nvupdate.exe - Powered by Reason Core Security