updatetask.exe

This is part of various InstallCore adware bundles and is designed to run daily and maintain the current state of the installed product(s) offeres (mostly unwanted adware) by connecting to a remote server for configuration instructions. The application updatetask.exe has been detected as adware by 6 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time.
MD5:
f7ca5db905983096d83cbaec99479290

SHA-1:
64d1b38fe4de256d38199ef188828865ca30a1db

SHA-256:
92587050653c540ef288d98c4cae80ed07cb2c6a4f668f802f9eb2fef9bf8472

Scanner detections:
6 / 68

Status:
Adware

Explanation:
The update task for the InstallCore download manager.

Analysis date:
4/18/2024 5:30:31 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
PUA.Win32.DealPly
4.0.3.15411

ESET NOD32
Win32/DealPly.AI potentially unwanted (variant)
9.11436

Kaspersky
not-a-virus:HEUR:AdWare.Win32.DealPly
14.0.0.2209

Panda Antivirus
Trj/Genetic.gen
15.04.11.04

Reason Heuristics
PUP.UpdateProc.Task
15.4.11.0

Sophos
DealPly Updater
4.98

File size:
454.5 KB (465,408 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\run_dregol\updateproc\updatetask.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:28GraAU0fdzG9eTvoVUdNnKWCR9p7DXE74lQqUZsuso+kShbC44Ir:Mr3U09G4oVUHFCfy74PUmusgo/

Entry address:
0x62140

Entry point:
55, 8B, EC, 83, C4, F0, B8, A0, 1F, 46, 00, E8, C8, 4D, FA, FF, A1, 1C, 3F, 46, 00, 8B, 00, E8, C4, 9C, FE, FF, B9, 74, 61, 46, 00, A1, 1C, 3F, 46, 00, 8B, 00, 8B, 15, 78, 1D, 44, 00, E8, C5, 9C, FE, FF, A1, 74, 61, 46, 00, E8, C7, FD, FF, FF, A1, 1C, 3F, 46, 00, 8B, 00, E8, 2F, 9D, FE, FF, E8, 72, 26, FA, FF, 8B, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.6062

Developed / compiled with:
Microsoft Visual C++

Code size:
388.5 KB (397,824 bytes)

Scheduled Task
Task name:
Run_dregol

Trigger:
Daily (Runs daily at 1:30:00 AM)


Remove updatetask.exe - Powered by Reason Core Security