internetexplorer_updater.exe

File Validated

This is the InstallMetrix bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application internetexplorer_updater.exe by File Validated has been detected as adware by 4 anti-malware scanners. The program is a setup application that uses the InstallMetrix Software installer. With this installer, users are expecting to download Internet Explorer but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
File Validated  (signed and verified)

MD5:
4b5e975d0f766810ba3352b8b11c242b

SHA-1:
377a3b44882c4b48d392e6a673e483f86d17ab0d

SHA-256:
29d46d917e69a46d53b0ff719d77ade2720f9b6b4fb64208f24ce135db943beb

Scanner detections:
4 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/23/2024 8:10:23 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.Domaiq.215
9.0.1.05190

ESET NOD32
Win32/Adware.InstallMetrix (variant)
9.11493

Reason Heuristics
PUP.InstallMetrix.FileValidated
15.5.8.23

File size:
1.1 MB (1,144,072 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallMetrix Software

Language:
English (United Kingdom)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\internetexplorer_updater.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
2/26/2015 7:00:00 PM

Valid to:
2/27/2016 6:59:59 PM

Subject:
CN=File Validated, OU=File Validated, O=File Validated, L=San Francisco, S=California, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1C96D72469336B0857534EE1D7E9701D

File PE Metadata
Compilation timestamp:
4/17/2015 8:53:19 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:Itb20pkaCqT5TBWgNQ7aWQ8P/tCmjcl/qe1FyGdI6A:RVg5tQ7aWpP/tCmAjWGS5

Entry address:
0x25F74

Entry point:
E8, 6A, CE, 00, 00, E9, 7F, FE, FF, FF, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 58, 01, 4C, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 70, A3, 4B, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 58, 01, 4C, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00, F7, C6, 03, 00...
 
[+]

Entropy:
7.0550

Code size:
557.5 KB (570,880 bytes)

Remove internetexplorer_updater.exe - Powered by Reason Core Security