ContentExplorer.exe

Lake Ventures LLC

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application ContentExplorer.exe by Lake Ventures has been detected as adware by 2 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘ContentExplorer’. This file is typically installed with the program ContentExplorer by Lake Ventures LLC which is a potentially unwanted software program.
Publisher:
ContentExplorer  (signed by Lake Ventures LLC)

Product:
ContentExplorer

Version:
8.0

MD5:
2754f2f3bcb9c46685ce119123e5d1fa

SHA-1:
66386a76b59b68f4c9736f73bfade711f1d546cb

SHA-256:
86c9647bcc6ecbd2b30a06bc564f7c294943c31616dc9677b0f21f8247f2dd8f

Scanner detections:
2 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 12:45:17 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.MSIL.Gen
7.11.141.68

Reason Heuristics
PUP.LakeVentures.P
14.6.24.22

File size:
2.3 MB (2,429,680 bytes)

Product version:
8.0

Copyright:
Copyright © ContentExplorer 2014

Original file name:
ContentExplorer.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\contentexplorer\contentexplorer.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
12/17/2013 5:22:44 PM

Valid to:
12/17/2014 5:22:44 PM

Subject:
CN=Lake Ventures LLC, O=Lake Ventures LLC, L=Aliso Viejo, S=California, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B14BBCA37F140

File PE Metadata
Compilation timestamp:
6/24/2014 4:48:06 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:lxit8HMlPpD5phN+CWOze0qcRGIfmkCJIMtqHwqmS6daVX:TMppD5phNpJa0VlBXMt01mSNVX

Entry address:
0x250096

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.3 MB (2,417,152 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ContentExplorer

Command:
"C:\users\{user}\appdata\roaming\contentexplorer\contentexplorer.exe"


The file ContentExplorer.exe has been discovered within the following programs.

ContentExplorer  by Lake Ventures LLC
From the Terms and Conditions: "Content Explorer is ad-supported. During general internet usage on sites where Content Explorer operates, users may see additional banner, search, pop-up, pop-under, and in-text link advertisements.
ContentExplorer.net
85% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-209-12-138.compute-1.amazonaws.com  (54.209.12.138:80)

TCP (HTTP):
Connects to ec2-52-2-31-1.compute-1.amazonaws.com  (52.2.31.1:80)

TCP (HTTP):
Connects to ec2-52-55-229-79.compute-1.amazonaws.com  (52.55.229.79:80)

TCP (HTTP):
Connects to snt-re3-8a.sjc.dropbox.com  (108.160.162.105:80)

TCP (HTTP):
Connects to server-54-239-172-5.atl50.r.cloudfront.net  (54.239.172.5:80)

TCP (HTTP):
Connects to server-54-230-4-133.dfw3.r.cloudfront.net  (54.230.4.133:80)

TCP (HTTP):
Connects to rtr1.l7.search.vip.bf1.yahoo.com  (66.196.86.81:80)

TCP (HTTP):
Connects to l1.ycs.vip.nyc.yahoo.com  (216.115.104.240:80)

TCP (HTTP):
Connects to hosted-by.leaseweb.com  (199.115.115.70:80)

TCP (HTTP):
Connects to ec2-54-85-204-114.compute-1.amazonaws.com  (54.85.204.114:80)

TCP (HTTP):
Connects to ec2-54-236-190-56.compute-1.amazonaws.com  (54.236.190.56:80)

TCP (HTTP):
Connects to ec2-54-215-14-153.us-west-1.compute.amazonaws.com  (54.215.14.153:80)

TCP (HTTP):
Connects to ec2-54-213-2-7.us-west-2.compute.amazonaws.com  (54.213.2.7:80)

TCP (HTTP):
Connects to ec2-54-208-30-101.compute-1.amazonaws.com  (54.208.30.101:80)

TCP (HTTP):
Connects to ec2-54-186-141-248.us-west-2.compute.amazonaws.com  (54.186.141.248:80)

TCP (HTTP):
Connects to ec2-54-175-63-43.compute-1.amazonaws.com  (54.175.63.43:80)

TCP (HTTP):
Connects to ec2-52-87-60-86.compute-1.amazonaws.com  (52.87.60.86:80)

TCP (HTTP):
Connects to ec2-52-6-61-36.compute-1.amazonaws.com  (52.6.61.36:80)

TCP (HTTP):
Connects to ec2-52-6-38-43.compute-1.amazonaws.com  (52.6.38.43:80)

TCP (HTTP):
Connects to ec2-52-6-217-161.compute-1.amazonaws.com  (52.6.217.161:80)

Remove ContentExplorer.exe - Powered by Reason Core Security