updater26766.exe

Discount Buddy

Innovative Apps

This is part of a distribution package that is classified as adware distributed by 50onRed. This adware is used to interact with the installed web browsers and inject ads and modify the default search and homepages. The application updater26766.exe, “Discount Buddy exe” by Innovative Apps has been detected as adware by 5 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered by a time event.
Publisher:
215 Apps  (signed by Innovative Apps)

Product:
Discount Buddy

Description:
Discount Buddy exe

Version:
1000.1000.1000.1000

MD5:
745099e63ffc6c7a2b1ff11f49f55b59

SHA-1:
15b623fbc0b2bbe9010a4b3ebe34a61937e47685

SHA-256:
758bcd54dadc36af7a4f3cab1a433b2466766c7dc23432d098bfdc2d227c865f

Scanner detections:
5 / 68

Status:
Adware

Explanation:
May modify the web browser's settings including changing the homepage and search provider in addition to delivering ads (by injecting banner and text-links directly in the webpage).

Analysis date:
7/12/2025 4:14:29 AM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Trojan.Adw.Task.InnovativeApps.M
2013.8.3.17

ESET NOD32
Win32/Toolbar.CrossRider (variant)
7.8631

herdProtect (fuzzy)
2013.12.20.15

Reason Heuristics
Trojan.MyStart.Task.M
14.8.7.17

Trend Micro House Call
TROJ_GEN.F47V0302
7.2.354

File size:
205.4 KB (210,312 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
Discount Buddy.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\updater26766\updater26766.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
1/8/2013 4:00:00 PM

Valid to:
1/9/2014 3:59:59 PM

Subject:
CN=Innovative Apps, O=Innovative Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5419E32FDAD7A6E5666A35066C5EAAC5

File PE Metadata
Compilation timestamp:
1/15/2013 5:01:55 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:S/2e1jiykkaE5dKvKJZltWRkWTpJitu8xQAei7MxNEndGM//oH:/e9iykqZvlt4k8Jkn+Aei7MxvMW

Entry address:
0x15B31

Code size:
158 KB (161,792 bytes)

Scheduled Task
Task name:
Updater26766.exe

Trigger:
Time (Next runs on 8/3/2013 at 2:46 AM)


Remove updater26766.exe - Powered by Reason Core Security