dce4installer.exe

Software Updater LLC

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application dce4installer.exe by Software Updater has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. It is also typically executed from the user's temporary directory.
Publisher:
Software Updater LLC  (signed and verified)

MD5:
1a399506d0c39e4cd9587a96bb61c4a6

SHA-1:
7bc22aa3af19d066f05c0a5d7e73a10d4b867116

SHA-256:
af60fdebc54222e197d3f0ee59af9513fd22d58efc1aaedeae54dc38e8f2aa74

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 2:38:46 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.212.236

avast!
Installer-T [PUP]
150129-1

AVG
Generic
2016.0.3185

Baidu Antivirus
PUA.Win32.Vittalia
4.0.3.15227

Dr.Web
Trojan.DownLoader10.36044
9.0.1.05190

ESET NOD32
Win32/Vittalia.N potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/Vittalia
2/27/2015

K7 AntiVirus
Unwanted-Program
13.1915113

Malwarebytes
PUP.Optional.Vittalia
v2015.02.27.11

McAfee
Trojan.Artemis!3E290F1CE9D3
16.8.708.2

NANO AntiVirus
Trojan.Win32.Siggen6.dlmmrv
0.30.0.296

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Reason Heuristics
PUP.SoftwareUpdater
15.2.27.23

Sophos
Generic PUA GM
4.98

VIPRE Antivirus
Threat.4782551
37588

File size:
2.9 MB (3,025,576 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM (using Nullsoft Install System)

Common path:
C:\users\{user}\appdata\local\temp\dce4installer.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
1/13/2014 6:50:03 AM

Valid to:
6/21/2016 12:31:04 PM

Subject:
CN=Software Updater LLC, O=Software Updater LLC, L=Wilmington, S=Delaware, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B6CAE0143C59A

File PE Metadata
Compilation timestamp:
12/5/2009 4:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:/kEFWyMEdTA80R1sF2sronSMxPIfQaZQ7iIJXHBJRzUfDMpXT2BIHPsQdSTDc+Q4:/NWyMES1S2NSMxPMZeBXHYKXTuwkQdml

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9916

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove dce4installer.exe - Powered by Reason Core Security