SaferUpdate.exe

Safer Update

Safer Technologies, Inc

The application SaferUpdate.exe by Safer Technologies, Inc has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler named SaferUpdateTaskMachineCore triggered to execute each time a user logs in.
Publisher:
Safer Technologies, Inc.  (signed by Safer Technologies, Inc)

Product:
Safer Update

Version:
1.3.99.0

MD5:
276f4b1d5259737d38e60bc30b565ba3

SHA-1:
89b6b4ec5d8f7f4c7df5b14f8d918d00d2f5934c

SHA-256:
d2612f0d66d0d5c4add8b11810d59ccf19f15db2bfafed390169350cdcf90b6a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
8/11/2025 10:18:09 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.9.24.15

File size:
143.4 KB (146,880 bytes)

Product version:
1.3.99.0

Copyright:
Safer Technologies, Inc.

Original file name:
SaferUpdate.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\safer technologies\update\saferupdate.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/25/2014 4:00:00 PM

Valid to:
2/26/2016 3:59:59 PM

Subject:
CN="Safer Technologies, Inc", OU=Applied Cryptography, O="Safer Technologies, Inc", STREET=2711 CENTERVILLE RD STE 400, L=NEW CASTLE, S=DE, PostalCode=19808, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00AD7775F77C246C94E75D0D23C8F43D9B

File PE Metadata
Compilation timestamp:
8/28/2015 6:49:15 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
3072:LoSEoPoOJpj2x6VzN+reKthfYoVu/p3+O687xCx437JDMYwPuTtivxZbksO2sM4l:UoNJpGGN+Al

Entry address:
0x7A92

Entry point:
E8, 34, 25, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, FF, 15, 80, 60, 41, 00, 6A, 01, A3, 44, 34, 41, 00, E8, 2C, 2B, 00, 00, FF, 75, 08, E8, 16, 2A, 00, 00, 83, 3D, 44, 34, 41, 00, 00, 59, 59, 75, 08, 6A, 01, E8, 12, 2B, 00, 00, 59, 68, 09, 04, 00, C0, E8, E4, 29, 00, 00, 59, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, 21, 9A, 00, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, 28, 32, 41, 00, 89, 0D, 24, 32, 41, 00, 89, 15, 20, 32, 41, 00, 89, 1D, 1C, 32, 41, 00, 89, 35, 18, 32, 41, 00, 89, 3D, 14...
 
[+]

Entropy:
5.7210

Code size:
66.5 KB (68,096 bytes)

Scheduled Task
Task name:
SaferUpdateTaskMachineCore

Trigger:
Logon (Runs on logon)

Description:
Keeps your Safer software up to date. If this task is disabled or stopped, your Safer software will not be kept up to date, meaning security vulnerabi


Remove SaferUpdate.exe - Powered by Reason Core Security