updatestar_enu_installer.exe

UpdateStar GmbH

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application updatestar_enu_installer.exe by UpdateStar GmbH has been detected as a potentially unwanted program by 5 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from static.updatestar.net.
Publisher:
UpdateStar GmbH  (signed and verified)

MD5:
ea6721011e1ba0ed433ff5cb08363a0b

SHA-1:
ba64c4c2c1d1711bf6ac5aeb72b15921c2608924

SHA-256:
c46eee131b7e72d06ba1c18bed455cfb1dcb5f8f3e6d943076f25dccff7020a0

Scanner detections:
5 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/17/2024 11:32:43 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAdware
1.3.0.7062

Dr.Web
Trojan.InstallCore.579
9.0.1.0220

McAfee
Artemis!EA6721011E1B
5600.6680

Panda Antivirus
PUP/Multitoolbar
15.08.08.02

Reason Heuristics
PUP.installCore (M)
15.8.8.2

File size:
272.9 KB (279,472 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\users\{user}\downloads\updatestar_enu_installer.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/1/2013 8:00:00 PM

Valid to:
1/2/2016 7:59:59 PM

Subject:
CN=UpdateStar GmbH, O=UpdateStar GmbH, STREET=Hauptstraße 20, L=Berlin, S=Berlin, PostalCode=10827, C=DE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009ED227324380B40DDE36C8D31A33831F

File PE Metadata
Compilation timestamp:
4/23/2015 12:23:53 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:kRukgb7nWxM2YaJhX0irPF0IscSeypXAynZi0FsSjdtGgkEbj:kR26Eir90Isc1ypbwGjdgzEbj

Entry address:
0x9E660

Entry point:
60, BE, 00, E0, 45, 00, 8D, BE, 00, 30, FA, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
260 KB (266,240 bytes)

The file updatestar_enu_installer.exe has been seen being distributed by the following URL.

Remove updatestar_enu_installer.exe - Powered by Reason Core Security