ContentExplorer.exe

Lake Ventures LLC

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application ContentExplorer.exe by Lake Ventures has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. This executable runs as a local area network (LAN) Internet proxy server listening on port 49191 and has the ability to intercept and modify all inbound and outbound Internet traffic on the local host. This file is typically installed with the program ContentExplorer by Lake Ventures LLC which is a potentially unwanted software program.
Publisher:
ContentExplorer  (signed by Lake Ventures LLC)

Product:
ContentExplorer

Version:
8.0

MD5:
2662cb2dcabc84a85602f1199a6c5d7a

SHA-1:
8caffaf260d0ddd2ba8ec280c620877c258f4a47

SHA-256:
45ea52119088a07c1fd2998165705931be55d00b9bb0698b09319aaa1c1e4c76

Scanner detections:
8 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 12:41:43 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.MSIL.Gen
7.11.141.68

Baidu Antivirus
Adware.MSIL.iBryte
4.0.3.141016

Dr.Web
Adware.iBryte.491
9.0.1.0289

ESET NOD32
MSIL/Adware.iBryte (variant)
8.10574

McAfee
Artemis!3C5098BEA3C0
5600.6975

Reason Heuristics
PUP.LakeVentures.P
14.10.16.16

Sophos
Generic PUA CJ
4.98

Trend Micro House Call
Suspicious_GEN.F47V0819
7.2.289

File size:
2.3 MB (2,429,680 bytes)

Product version:
8.0

Copyright:
Copyright © ContentExplorer 2014

Original file name:
ContentExplorer.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\contentexplorer\contentexplorer.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
12/17/2013 4:22:44 PM

Valid to:
12/17/2014 4:22:44 PM

Subject:
CN=Lake Ventures LLC, O=Lake Ventures LLC, L=Aliso Viejo, S=California, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B14BBCA37F140

File PE Metadata
Compilation timestamp:
10/16/2014 1:00:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:6xize6Sz63kVr1s3sKBmtgpq7cqb+SZ+e5HBNhUuKM8Ssf:6Fhs3JEtIq7xhZnHvsM8Sy

Entry address:
0x250092

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.7825

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.3 MB (2,417,152 bytes)

Local Proxy Server
Proxy for:
Internet Settings

Local host address:
http://127.0.0.1:49191/

Local host port:
49191

Default credentials:
No


The file ContentExplorer.exe has been discovered within the following program.

ContentExplorer  by Lake Ventures LLC
From the Terms and Conditions: "Content Explorer is ad-supported. During general internet usage on sites where Content Explorer operates, users may see additional banner, search, pop-up, pop-under, and in-text link advertisements.
ContentExplorer.net
85% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.jam-software.de  (178.63.45.149:80)

TCP (HTTP):
Connects to servedbyadbutler.com  (64.34.33.202:80)

TCP (HTTP):
Connects to ord08s09-in-f20.1e100.net  (74.125.225.148:80)

TCP (HTTP):
Connects to ip-108-60-149-217.static.atlanticmetro.net  (108.60.149.217:80)

TCP (HTTP):
Connects to iad23s08-in-f28.1e100.net  (74.125.228.124:80)

TCP (HTTP):
Connects to hwcdn.net  (69.16.175.42:80)

TCP (HTTP):
Connects to ec2-23-23-226-131.compute-1.amazonaws.com  (23.23.226.131:80)

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):
Connects to 74-220-214-123.unifiedlayer.com  (74.220.214.123:80)

TCP (HTTP):
Connects to 22.32.199.65.philadelphia.google-ggc.verizon.com  (65.199.32.22:80)

Remove ContentExplorer.exe - Powered by Reason Core Security