securityscan_release.exe

UpdateStar GmbH

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application securityscan_release.exe by UpdateStar GmbH has been detected as a potentially unwanted program by 14 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
UpdateStar GmbH  (signed and verified)

MD5:
bd74e713406e01f6fd0948003041db72

SHA-1:
1bebb772ace49839c776d6723cb3fc534df561b7

SHA-256:
8fb416e3d4f512695f6d8b45fb97127539386431e4fa399d6b8951276e23cefb

Scanner detections:
14 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 5:38:39 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Kryptik
7.1.1

Avira AntiVirus
7.11.164.144

AVG
Generic
2015.0.3398

Baidu Antivirus
Trojan.Win32.Kryptik
4.0.3.14910

Comodo Security
UnclassifiedMalware
18624

Dr.Web
Trojan.Packed.24524
9.0.1.0211

ESET NOD32
Win32/Kryptik.ATFX (variant)
8.9979

herdProtect (fuzzy)
2014.9.10.6

K7 AntiVirus
Trojan
13.181.12872

Malwarebytes
v2014.07.30.04

Qihoo 360 Security
Win32/Trojan.443
1.0.0.1015

Reason Heuristics
PUP.UpdateStarGmbH.U
14.7.30.4

Trend Micro House Call
Suspicious_GEN.F47V0615
7.2.253

VIPRE Antivirus
Trojan.Win32.Generic
30524

File size:
723.3 KB (740,688 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\securityscan_release.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/10/2014 2:00:00 AM

Valid to:
6/11/2015 1:59:59 AM

Subject:
CN=UpdateStar GmbH, OU=IT, O=UpdateStar GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
71A04D21E9F4BB6E19C3CB7D720E6245

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:w7EvpVehSPZwKt2d8a5mh8EzvCW/MGTYGYWARi+uX3wGpWKFeCrSMl:w7EvTHasmEzvD9YWAvhGpWKFhFl

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

Remove securityscan_release.exe - Powered by Reason Core Security