updatetask.exe

This is part of various InstallCore adware bundles and is designed to run daily and maintain the current state of the installed product(s) offeres (mostly unwanted adware) by connecting to a remote server for configuration instructions. The application updatetask.exe has been detected as adware by 5 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named Speedial triggered daily at a specified time.
MD5:
40e05dca12980d6d7d6cca9a1278026c

SHA-1:
17d0dd72c31bb3517ff0d629b935f2ca17ad47f2

SHA-256:
758c6c07561dc576e97899462aaf76227e0539e76d163f3cb1e9668036d56ec4

Scanner detections:
5 / 68

Status:
Adware

Explanation:
The update task for the InstallCore download manager.

Analysis date:
4/18/2024 7:52:56 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
APPL/DealPly.Q.85
7.11.163.92

Baidu Antivirus
Adware.Win32.DealPly
4.0.3.14722

ESET NOD32
Win32/DealPly.S potentially unwanted application
7.0.302.0

Reason Heuristics
PUP.UpdateProc.K
14.7.22.7

File size:
97.5 KB (99,840 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\speedial\updateproc\updatetask.exe

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:JzPqrVlGcN4uHMpXG5cM8QsUKNeLGr2J:J+rBN4us5VM8QvKoR

Entry address:
0x15964

Entry point:
55, 8B, EC, 83, C4, F0, B8, 0C, 59, 41, 00, E8, 60, F2, FE, FF, 6A, 01, 68, 10, 58, 41, 00, 68, 44, 58, 41, 00, 68, 78, 58, 41, 00, B9, A8, 59, 41, 00, BA, D4, 59, 41, 00, B8, D4, 59, 41, 00, E8, 1F, 6F, FF, FF, E8, 4A, E0, FE, FF, 00, 00, FF, FF, FF, FF, 22, 00, 00, 00, 70, 6F, 2D, 31, 31, 2C, 6F, 65, 60, 2B, 51, 2C, 75, 7A, 6A, 7A, 76, 6E, 6F, 2D, 30, 2C, 63, 78, 2B, 50, 2C, 6C, 69, 67, 2E, 79, 2D, 5B, 00, 00, FF, FF, FF, FF, 08, 00, 00, 00, 53, 70, 65, 65, 64, 69, 61, 6C, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.2743

Developed / compiled with:
Microsoft Visual C++

Code size:
82.5 KB (84,480 bytes)

Scheduled Task
Task name:
Speedial

Trigger:
Daily (Runs daily at 5:48 PM)

Action:
updatetask.exe \check


Remove updatetask.exe - Powered by Reason Core Security