updater.exe

Creative Island Media, LLC

Part of the branded Injekt adware package, the updater mechanism is an auto-starting program that is desigend to update the web browser extensions and protect the executables ChromeHelper, FirefoxHelper and IeHelper so that these programs can inject advertisments and generate popups in the user's web browser. The application updater.exe by Creative Island Media has been detected as adware by 24 anti-malware scanners. This file is typically installed with the program Updater by Creative Island Media, LLC which is a potentially unwanted software program.
Publisher:
Updater  (signed by Creative Island Media, LLC)

Product:
Updater

Description:
Updater service

Version:
1, 0, 0, 1

MD5:
94d753be54fa53eb62690b687cbd2c77

SHA-1:
002bef7e255cb25b9f93fd0ceb9ec4f9423fbd9b

SHA-256:
a7dccaf5caf95ff91e56a0134e552d91b83209e065c6b959191215cd9765d964

Scanner detections:
24 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/25/2024 8:00:30 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.NUR
469

Agnitum Outpost
PUA.Downware
7.1.1

Avira AntiVirus
TR/Trash.Gen
7.11.30.172

avast!
Win32:TubeDim-A [PUP]
2014.9-151023

AVG
Generic
2016.0.2947

Bitdefender
Adware.Agent.NUR
1.0.20.1480

Bkav FE
W32.Clod4a8.Trojan
1.3.0.4613

Dr.Web
Adware.Plugin.947
9.0.1.0296

Emsisoft Anti-Malware
Adware.Agent.NUR
8.15.10.23.03

ESET NOD32
Win32/Toolbar.WebApp.A potentially unwanted application
9.7.0.302.0

F-Secure
Adware.Agent.NUR
11.2015-23-10_6

G Data
Win32.Application.TubeDimmer
15.10.24

IKARUS anti.virus
AdWare.Agent
t3scan.1.8.6.0

Malwarebytes
PUP.Optional.Updater.A
v2015.10.23.03

McAfee
Artemis!94D753BE54FA
5600.6603

MicroWorld eScan
Adware.Agent.NUR
16.0.0.888

Norman
Malware
11.20151023

nProtect
Adware.Agent.NUR
15.03.25.01

Reason Heuristics
PUP.Injekt.CreativeIslandMedia (M)
15.10.23.15

Sophos
Search Donkey
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
9552

Trend Micro House Call
TROJ_GEN.F47V1106
7.2.296

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

VIPRE Antivirus
Injekt
34538

File size:
305.9 KB (313,208 bytes)

Product version:
1, 0, 0, 1

Original file name:
updater.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\updater\updater.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/21/2013 2:00:00 AM

Valid to:
5/22/2014 1:59:59 AM

Subject:
CN="Creative Island Media, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Creative Island Media, LLC", L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
68F23F4D2767F6491DEA9186F2E5CB89

File PE Metadata
Compilation timestamp:
10/23/2013 10:06:59 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:RL3CzMRBuNCt6XVFJRoy71YTUjQYouVeZVZMaZVfbOYh1W89slSVAghzOuKsIBk2:RLSzMRXuVFTRSowZvHfKSpQqiuVGp

Entry address:
0x1ED07

Entry point:
E8, 53, 96, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8, 1C, D5, FF, FF, 59, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 10, A1, 10, EC, 43, 00, 33, C5, 89, 45, FC, 8B, 55, 18, 53, 33, DB, 56, 57, 3B, D3, 7E, 1F, 8B, 45, 14, 8B, CA, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, C2, 2B, C1, 48, 3B, C2, 7D, 01, 40, 89, 45, 18, 89, 5D, F8, 39, 5D, 24, 75, 0B, 8B, 45, 08, 8B, 00, 8B, 40, 04, 89, 45, 24, 8B, 35, 44, 41, 43, 00...
 
[+]

Code size:
200.5 KB (205,312 bytes)

The file updater.exe has been discovered within the following program.

Updater  by Creative Island Media, LLC
This is the updater program installed with the company's TubeDimmer software which is typically installed through a bundled offer and is potentially unwanted.
www.injekt.com
82% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to update.betterxperience.com  (54.218.62.24:80)

TCP (HTTP):
Connects to d.pullupdate.com  (54.230.15.37:80)

TCP (HTTP):
Connects to d.betterxperience.com  (54.230.13.123:80)

 
http://d.betterxperience.com/updater/dedu.txt

Remove updater.exe - Powered by Reason Core Security