updater.exe

Creative Island Media, LLC

Part of the branded Injekt adware package, the updater mechanism is an auto-starting program that is desigend to update the web browser extensions and protect the executables ChromeHelper, FirefoxHelper and IeHelper so that these programs can inject advertisments and generate popups in the user's web browser. The application updater.exe by Creative Island Media has been detected as adware by 23 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Updater’.
Publisher:
Updater  (signed by Creative Island Media, LLC)

Product:
Updater

Description:
Updater service

Version:
1, 0, 0, 1

MD5:
8d1893d2339c6e1429494d21dd682556

SHA-1:
7df57a1f4c0b5ad2c564ce026c8cbe8ba3b36894

SHA-256:
4f660080142eeded5920deac2ef45975cfae0e60677e81399a2cdb8f7d4938f9

Scanner detections:
23 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/19/2024 12:15:07 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.NUE
682

Agnitum Outpost
PUA.Downware
7.1.1

Avira AntiVirus
TR/Trash.Gen
7.11.30.172

avast!
Win32:TubeDim-A [PUP]
2014.9-150324

Bitdefender
Adware.Agent.NUE
1.0.20.415

Bkav FE
W32.Clod4a8.Trojan
1.3.0.4613

Dr.Web
Adware.Plugin.128
9.0.1.083

Emsisoft Anti-Malware
Adware.Agent.NUR
8.15.03.24.03

ESET NOD32
Win32/Toolbar.WebApp.A potentially unwanted application
9.7.0.302.0

F-Secure
Adware.Agent.NUR
11.2015-24-03_3

G Data
Win32.Application.TubeDimmer
15.3.22

IKARUS anti.virus
AdWare.Agent
t3scan.2.2.29

Malwarebytes
PUP.Optional.TubeDimmer
v2015.03.24.03

McAfee
Artemis!A5F634DAE5C0
5600.6816

MicroWorld eScan
Adware.Agent.NUE
16.0.0.249

Norman
Malware
11.20150324

nProtect
Adware.Agent.NUE
14.02.02.01

Reason Heuristics
PUP.Startup.Injekt
15.3.24.15

Sophos
Search Donkey
4.97

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
9978

Trend Micro House Call
TROJ_GEN.F47V1106
7.2.83

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

VIPRE Antivirus
Injekt
29624

File size:
290.4 KB (297,336 bytes)

Product version:
1, 0, 0, 1

Original file name:
updater.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\updater\updater.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/20/2013 5:00:00 PM

Valid to:
5/21/2014 4:59:59 PM

Subject:
CN="Creative Island Media, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Creative Island Media, LLC", L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
68F23F4D2767F6491DEA9186F2E5CB89

File PE Metadata
Compilation timestamp:
10/2/2013 1:57:21 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:DaVootm2hhRFpri2Qsf/m5/Y/A1T1DWFR:DaaQm2PRDrigf/4t7WFR

Entry address:
0x1C477

Entry point:
E8, 46, 96, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8, 3C, D4, FF, FF, 59, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 10, A1, 30, AB, 43, 00, 33, C5, 89, 45, FC, 8B, 55, 18, 53, 33, DB, 56, 57, 3B, D3, 7E, 1F, 8B, 45, 14, 8B, CA, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, C2, 2B, C1, 48, 3B, C2, 7D, 01, 40, 89, 45, 18, 89, 5D, F8, 39, 5D, 24, 75, 0B, 8B, 45, 08, 8B, 00, 8B, 40, 04, 89, 45, 24, 8B, 35, 4C, 01, 43, 00...
 
[+]

Entropy:
6.4274

Code size:
187.5 KB (192,000 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Updater

Command:
C:\ProgramData\updater\updater.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to update.betterxperience.com  (54.218.62.24:80)

TCP (HTTP):
Connects to d.pullupdate.com  (54.230.15.37:80)

TCP (HTTP):
Connects to d.betterxperience.com  (54.230.13.123:80)

 
http://d.betterxperience.com/updater/dedu.txt

Remove updater.exe - Powered by Reason Core Security