updater.exe

Installer

Amonetize ltd.

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application updater.exe by Amonetize ltd has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the Amonetize Downloader installer. It runs as a scheduled task under the Windows Task Scheduler named AmiUpdXp triggered to execute each time a user logs in. This file is typically installed with the program Software Version Updater by Amonetize ltd. which is a potentially unwanted software program. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Amonetize ltd.  (signed and verified)

Product:
Installer

Description:
Updater

Version:
1.1.3.8

MD5:
6502ac8a5b25f5db27116ccf5cd69b7b

SHA-1:
04a407fd7055516134d38ab2ec0f453f3775cdd5

SHA-256:
c53107e7a855bc9f3bbb0c052f8b2e9b2db149c5925dfed9be2126cdbab0c17e

Scanner detections:
19 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
10/20/2018 4:37:53 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.Amonetiz
2014.02.23

Avira AntiVirus
APPL/Amonetize.D
7.11.124.216

avast!
Win32:Amonetize-D [PUP]
2014.9-140223

AVG
MalSign.Generic
2015.0.3555

Bkav FE
W32.Clod347.Trojan
1.3.0.4562

Boost by Reason
Optional.Task.Amonetizeltd.H
188838

Dr.Web
Adware.Downware.1528
9.0.1.054

ESET NOD32
Win32/Amonetize.AC (variant)
8.9459

Fortinet FortiGate
Riskware/Amonetize
2/23/2014

IKARUS anti.virus
Win32.Malware
t3scan.2.2.29

K7 AntiVirus
Unwanted-Program
13.174.10306

Malwarebytes
PUP.Optional.Amonetize.A
v2014.02.23.12

McAfee
Artemis!6502AC8A5B25
5600.7211

Reason Heuristics
PUP.Task.Amonetizeltd.H
14.8.7.20

Sophos
Amonetize
4.97

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10435

Trend Micro House Call
TROJ_GEN.F47V1118
7.2.54

Trend Micro
ADW_AMONETIZE
10.465.23

VIPRE Antivirus
Amonetize
26746

File size:
281.5 KB (288,296 bytes)

Product version:
2.1.12

Copyright:
(c) 2012-2014, All rights reserved.

Original file name:
Upd.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Amonetize Downloader

Common path:
C:\users\{user}\appdata\local\swvupdater\updater.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/19/2013 4:00:00 AM

Valid to:
6/19/2015 3:59:59 AM

Subject:
CN=Amonetize ltd., O=Amonetize ltd., L=Raanana, S=Alberta, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
235E7B2F1D4E0152189F6381E2BA8C97

File PE Metadata
Compilation timestamp:
2/22/2014 7:39:16 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:zZAM9dHdyKo86TYStucSpjFDIZOKWMJb0llAAU/1U541FaEZ:9AMnHdSsStXexDIZO8Q9U/1Q4vaEZ

Entry address:
0x9C6F0

Entry point:
60, BE, 00, B0, 45, 00, 8D, BE, 00, 60, FA, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Packer / compiler:
UPX 2.90LZMA]

Code size:
264 KB (270,336 bytes)

Scheduled Task
Task name:
AmiUpdXp

Trigger:
Logon (Runs on logon)

Description:
Software Version Updater


The file updater.exe has been discovered within the following program.

Software Version Updater  by Amonetize ltd.
The program is distributed by Amonetize ltd., a program bundling/installation monitization platform. "We provide our own installer software component. Our installer easily integrates with any Windows software product.
www.amonetize.com
80% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ec2-54-225-181-84.compute-1.amazonaws.com  (54.225.181.84:80)

Remove updater.exe - Powered by Reason Core Security