updatetask.exe

This is part of various InstallCore adware bundles and is designed to run daily and maintain the current state of the installed product(s) offeres (mostly unwanted adware) by connecting to a remote server for configuration instructions. The application updatetask.exe has been detected as adware by 5 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time.
MD5:
a9fdea7c7112db8b74ef4e123d95f816

SHA-1:
a645887207b3b55f090294ff38de19b7f4fd98aa

SHA-256:
71178cc6a35dfb3db7549cb9433bd330cb78ea14988ecdd3364963991369cb49

Scanner detections:
5 / 68

Status:
Adware

Explanation:
The update task for the InstallCore download manager.

Analysis date:
8/27/2026 1:09:44 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.DealPly
4.0.3.14217

Boost by Reason
Optional.Task.K
188432

ESET NOD32
Win32/DealPly (variant)
8.9434

Reason Heuristics
PUP.UpdateProc.Task.K
14.3.3.16

Trend Micro House Call
TROJ_GEN.F47V0215
7.2.48

File size:
108.5 KB (111,104 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\digitalsites\updateproc\updatetask.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:DzPqTcOPkXJi2Xti3Yn9/j2GNLb6WSwLGGRn+++++++++++++++++++++++++++a:D2TFP+EUH5NKWHN3

Entry address:
0x15C30

Entry point:
55, 8B, EC, 83, C4, F0, B8, D8, 5B, 41, 00, E8, 94, EF, FE, FF, 33, C0, 55, 68, 4F, 5D, 41, 00, 64, FF, 30, 64, 89, 20, E8, 91, CA, FE, FF, 85, C0, 0F, 8E, C0, 00, 00, 00, B8, 6C, 7C, 41, 00, BA, 64, 5D, 41, 00, E8, C2, DE, FE, FF, 83, 3D, 6C, 7C, 41, 00, 00, 75, 0F, B8, 6C, 7C, 41, 00, BA, 74, 5D, 41, 00, E8, B6, E0, FE, FF, B8, 6C, 7C, 41, 00, 8B, 0D, 6C, 7C, 41, 00, BA, 84, 5D, 41, 00, E8, E5, E0, FE, FF, 83, 3D, 6C, 7C, 41, 00, 00, 75, 0F, B8, 6C, 7C, 41, 00, BA, 94, 5D, 41, 00, E8, 89, E0, FE, FF, B8...
 
[+]

Code size:
84 KB (86,016 bytes)

Scheduled Task
Task name:
Digital Sites

Trigger:
Daily (Runs daily at 21:27)

Action:
updatetask.exe \check


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-243-159-209.compute-1.amazonaws.com  (54.243.159.209:80)

TCP (HTTP):
Connects to ec2-54-225-201-98.compute-1.amazonaws.com  (54.225.201.98:80)

TCP (HTTP):
Connects to ec2-107-21-93-207.compute-1.amazonaws.com  (107.21.93.207:80)

TCP (HTTP):
Connects to bits-lb.esams.wikimedia.org  (91.198.174.202:80)

Remove updatetask.exe - Powered by Reason Core Security