updatetask.exe

Volonet Ltd

This is part of various InstallCore adware bundles and is designed to run daily and maintain the current state of the installed product(s) offeres (mostly unwanted adware) by connecting to a remote server for configuration instructions. The application updatetask.exe by Volonet has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler named Funmoods triggered daily at a specified time. This file is typically installed with the program MaintenanceService-Funmoods by Volonet Ltd which is a potentially unwanted software program.
Publisher:
Volonet Ltd  (signed and verified)

MD5:
f8981a707176c89162202985f45a5947

SHA-1:
43b0f631dd367bb37a6fedf6eff3ab65db87d8aa

SHA-256:
a3448ce00845fd96c0e902c1b5fdd1087889d3d98398d95435228a1275e12030

Scanner detections:
1 / 68

Status:
Adware

Explanation:
The update task for the InstallCore download manager.

Analysis date:
5/10/2024 3:53:33 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.UpdateProc (M)
16.11.30.0

File size:
97.4 KB (99,704 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\funmoods\updateproc\updatetask.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/11/2012 5:30:00 AM

Valid to:
11/26/2013 5:29:59 AM

Subject:
CN=Volonet Ltd, O=Volonet Ltd, STREET=hazfira 19, L=Tel Aviv, S=Israel, PostalCode=67778, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D9EB879A7F4ADB713BB56F5D9EA449DA

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
1536:G6qfTsoUFYo/r+RGRdHmdc+P1shgdQCoivnv4e9cGuC9zA/wC3YAgTZt:YTTUiU+AYc+qgdQxivAe9cGuCO/9gT3

Entry address:
0x11FA0

Entry point:
55, 8B, EC, B9, 06, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, B8, 48, 1F, 41, 00, E8, FE, 2A, FF, FF, 33, C0, 55, 68, 31, 21, 41, 00, 64, FF, 30, 64, 89, 20, E8, 17, 07, FF, FF, 85, C0, 0F, 84, 41, 01, 00, 00, E8, 76, 74, FF, FF, E8, 3D, 92, FF, FF, 8D, 45, EC, E8, 71, 33, FF, FF, 83, 7D, EC, 00, 74, 17, B8, 48, 21, 41, 00, E8, D9, 8D, FF, FF, 40, 75, 0A, E8, 19, FC, FF, FF, E9, 12, 01, 00, 00, 68, 44, 0C, 41, 00, 68, 78, 0C, 41, 00, 8D, 55, E8, B8, 54, 21, 41, 00, E8, A9, 75, FF, FF, 8B, 45, E8, B9, 10...
 
[+]

Entropy:
6.5606

Developed / compiled with:
Microsoft Visual C++

Code size:
68.5 KB (70,144 bytes)

Scheduled Task
Task name:
Funmoods

Trigger:
Daily (Runs daily at AM 01:45:00)


The file updatetask.exe has been discovered within the following programs.

MaintenanceService-Funmoods  by Volonet Ltd
Tracks search behavior and modifies the user's Internet web browser's home page and search. Uses the InstallCore download manager to bundle additional software, including potentially unwanted software and adware.
funmoods.com
84% remove it
 
Powered by Should I Remove It?

Remove updatetask.exe - Powered by Reason Core Security