UpdaterService.exe

Updater

The application UpdaterService.exe has been detected as adware by 9 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Software Updater”.
Product:
Updater

Version:
1.1.0.7

MD5:
2acfb60f0822de4f62b044fb1d667d78

SHA-1:
00ebef9094714500b6aa2e79e2a72aab1472f002

SHA-256:
6b50772009d68809c67f82f2677aa6a26e1fe183fd0d95cc4a18ebf542e196d2

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Analysis date:
4/18/2024 12:38:32 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.Downloader
2014.08.23

Baidu Antivirus
PUA.MSIL.Vittalia
4.0.3.14822

ESET NOD32
MSIL/Vittalia.D potentially unwanted application
7.0.302.0

IKARUS anti.virus
PUA.Vittalia
t3scan.1.7.5.0

Malwarebytes
PUP.Optional.Vittalia
v2014.08.22.07

Reason Heuristics
PUP.OneInstall.O
14.8.22.18

Sophos
Vittalia
4.98

SUPERAntiSpyware
PUP.Vittalia/Variant
10405

VIPRE Antivirus
Threat.4782551
32210

File size:
55 KB (56,320 bytes)

Product version:
1.1.0.7

Copyright:
Copyright © 2014

Original file name:
UpdaterService.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\softwareupdater\updaterservice.exe

File PE Metadata
Compilation timestamp:
8/22/2014 10:05:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:0DQsJIpSxgQjwWAli+Hwm2VdjykRhzb8hrdmEe+YEvv:0c2IpX3li+l2Vdjyiz4hB17vv

Entry address:
0xC9DE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 48, 00, 00, 80, 10, 00, 00, 00, 60, 00, 00, 80, 18, 00, 00, 00, 78, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 02, 00, 00, 00, 90, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 00, 7F, 00, 00, A8, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
42.5 KB (43,520 bytes)

Service
Display name:
Software Updater

Service name:
SrvUpdater

Type:
Win32OwnProcess


Remove UpdaterService.exe - Powered by Reason Core Security