updater_setup.exe

INSTALL DOT EXE

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application updater_setup.exe, “Premium Installer ” by INSTALL DOT EXE has been detected as adware by 37 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. It is also typically executed from an Internet Explorer cache folder.
Publisher:
Premium Installer   (signed by INSTALL DOT EXE)

Product:
Premium Installer

Description:
Premium Installer

Version:
1.3.7.2

MD5:
ff2a00b413cd3ab088e20ef91d27aafd

SHA-1:
60d2fbb1fceb22a2c46d9f99e738cc4a4f5503f8

SHA-256:
1a92de38b9cb319641dc55a7e9045aed961c92c0dd67dc33f738216056b25d30

Scanner detections:
37 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/16/2024 10:59:42 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.593289
887

Agnitum Outpost
Riskware.AdWare
7.1.1

AhnLab V3 Security
2014.02.16

Avira AntiVirus
Adware/iBryte.O
7.11.125.52

avast!
Win32:IBryte-CF [PUP]
140813-1

AVG
Adware Skodna.Generic.AVQ
2014.0.4015

Baidu Antivirus
Adware.Win32.iBryte
4.0.3.1491

Bitdefender
Application.Generic.593289
1.0.20.1220

Clam AntiVirus
Win.Adware.Agent-6804
0.98/21411

Comodo Security
ApplicUnwnt
17791

Dr.Web
Adware.Downware.2183
9.0.1.05190

Fortinet FortiGate
W32/Buzus.gen!tr
9/1/2014

F-Prot
W32/Backdoor2.HTKO
v6.4.7.1.166

F-Secure
Application.Generic.593289
11.2014-01-09_2

G Data
Win32.Application.OptimumInstaller
14.9.24

IKARUS anti.virus
Trojan.Win32.Buzus
t3scan.2.2.29

K7 AntiVirus
Adware
13.175.10837

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3320

Malwarebytes
v2014.09.01.12

McAfee
Artemis!6DAF31AA36B7
5600.7021

MicroWorld eScan
Application.Generic.593289
15.0.0.732

NANO AntiVirus
Riskware.Win32.IBryte.csnspj
0.28.0.58491

nProtect
Trojan/W32.Buzus.2627880
14.04.30.01

Panda Antivirus
Trj/Genetic.gen
14.09.01.12

Qihoo 360 Security
HEUR/Malware.QVM10.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.INSTALLDOTEXE.N
14.9.1.0

Rising Antivirus
PE:PUF.PremiumInstaller!1.9F73
23.00.65.14830

SUPERAntiSpyware
10387

Total Defense
Win32/Tnega.MWULDGC
37.0.10864

Trend Micro House Call
TROJ_FRS.PMA001AD14
7.2.244

Trend Micro
TROJ_FRS.PMA001AD14
10.465.01

Vba32 AntiVirus
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
26494

Zillya! Antivirus
Trojan.Buzus.Win32.119960
2.0.0.1775

File size:
545.8 KB (558,888 bytes)

Product version:
1.3.7.2

Copyright:
Copyright (C) 2013 Premium Installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\updater_setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/3/2013 6:00:00 PM

Valid to:
9/20/2014 5:59:59 PM

Subject:
CN=INSTALL DOT EXE, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=INSTALL DOT EXE, L=Kansas City, S=Missouri, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4C8303B332693FCF64E1E7DFD7841493

File PE Metadata
Compilation timestamp:
2/22/2014 8:30:46 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:bbKw+hW/nmbD72L2146gN+8S/8xGhvI8MOZpA4z:CX72L21s7kthw8MOc4z

Entry address:
0x3CE88

Entry point:
E8, AA, 6C, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 00, 9E, 47, 00, E8, CA, 09, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, F8, 42, 48, 00, 77, 22, 6A, 04, E8, AD, 6E, 00, 00, 59, 83, 65, FC, 00, 56, E8, 0F, 7C, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, D6, 09, 00, 00, C3, 6A, 04, E8, 90, 6D, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 83, 3D, 54, 2F, 48, 00, 00, 75, 18, E8, E1, 61, 00, 00, 6A, 1E, E8, 09, 60, 00, 00, 68, FF, 00, 00, 00, E8, 94, 1F, 00, 00, 59, 59, A1...
 
[+]

Entropy:
6.4366

Code size:
408.5 KB (418,304 bytes)

Remove updater_setup.exe - Powered by Reason Core Security