How to remove GoogleUpdate.exe

GoogleUpdate.exe

The module GoogleUpdate.exe has been detected as Trojan.DisguiseService

GoogleUpdate.exe

GoogleUpdate.exe is a Windows file recorded in the ThreatInfo database. It is associated with Google Update. The reported company name is Google Inc.. The current detection status is Trojan.DisguiseService, based on the latest analysis from 2021-01-08 09:38:55 (5 years ago).

If GoogleUpdate.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.DisguiseService.

Product Name: Google Update
Company Name: Google Inc.
MD5: ef2899570ca0e05129be78681f8d2586
Size: 226 KB
First Published: 2021-01-08 09:30:24 (5 years ago)
Latest Published: 2021-01-08 09:38:55 (5 years ago)
Status: Trojan.DisguiseService (on last analysis)
Analysis Date: 2021-01-08 09:38:55 (5 years ago)
%programfiles%\google
%programfiles%\google
%programfiles%\google
%programfiles%\google

ThreatInfo has observed GoogleUpdate.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

Windows 8.1 100.0%

The most common operating system signal for GoogleUpdate.exe is Windows 8.1 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

GoogleUpdate.exe is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x000072f0

PE Sections:

Name Size of data MD5
.text 74240 7d597610109cdb24e391936a3616c6cd
.data 2048 ce971a45b22587da8119cbf58c011bbf
.idata 2560 27ee244943133bc92a72466af48c931f
.gfids 512 23eb579bb96ec5b41ccd68a1e5f8f62f
.rsrc 58368 503508605c59d43365bd080b3f5fb89f
.reloc 4096 b0a72ee4ef7eab063ead0b096c77542b

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information:

Download GridinSoft Anti-Malware - Removal tool for GoogleUpdate.exe