AutoUpdate.exe threat report

MD5 cea6c974fed7e3a55ba9a7c2fa2ab910
Latest seen 2024-11-04 23:11:19 (a year ago)
First seen 2024-11-04 23:11:19 (a year ago)
Size 3 MB
Publisher IObit
Product Smart Defrag

This report summarizes the file identity, detection status, publisher metadata, observed locations, and technical indicators for AutoUpdate.exe. ThreatInfo currently classifies this sample as PUP.Gen.

GridinSoft Anti-Malware detection

GridinSoft already detects this file

The latest ThreatInfo record shows AutoUpdate.exe detected as PUP.Gen. You can download GridinSoft Anti-Malware to scan the system and remove this detection if the file is present on your device.

Detection name
PUP.Gen
Last analysis
2024-11-04 23:11:19 (a year ago)
File hash
cea6c974fed7e3a55ba9a7c2fa2ab910
Download Anti-Malware

AutoUpdate.exe is a Windows file recorded in the ThreatInfo database. It is associated with Smart Defrag. The reported company name is IObit. The current detection status is PUP.Gen, based on the latest analysis from 2024-11-04 23:11:19 (a year ago).

If AutoUpdate.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as PUP.Gen.

Product Name: Smart Defrag
Company Name: IObit
MD5: cea6c974fed7e3a55ba9a7c2fa2ab910
Size: 3 MB
First Published: 2024-11-04 23:11:19 (a year ago)
Latest Published: 2024-11-04 23:11:19 (a year ago)
Status: PUP.Gen (on last analysis)
Analysis Date: 2024-11-04 23:11:19 (a year ago)
AutoUpdate.exe detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%sysdrive%\progammi da provare\iobit smart defrag pro v9.0.0.307 portable.rar\iobit smart defrag pro v9.0.0.307 portable\app

ThreatInfo has observed AutoUpdate.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Italy with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for AutoUpdate.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

AutoUpdate.exe is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0026d1c4

PE Sections:

Name Size of data MD5
.text 2531328 e704342dce44ee78e73284503ec5939d
.itext 12288 3d14547c7b82480d32b2df55d842423c
.data 99840 5d47f6912b2ca3c072c0e25510e11ab7
.bss 0 d41d8cd98f00b204e9800998ecf8427e
.idata 18432 8e4aa51be01e7714a8f72ee000506628
.edata 512 788a2e32a5ba67d08b4129487bc3e366
.tls 0 d41d8cd98f00b204e9800998ecf8427e
.rdata 512 4a7d9f5772e4508549c6b29df0d76cd2
.reloc 146944 664063de3dad8c09c9917eadf413782a
.rsrc 886784 19265f7b5d25169215cb27cf197b5e5b

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: