chrome_updater.exe

TODO:

File Verified

This is the InstallMetrix bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application chrome_updater.exe by File Verified has been detected as adware by 29 anti-malware scanners. The program is a setup application that uses the InstallMetrix Software installer. The installer is marketed through download protals and search ads as Google's Chrome web browser but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
TODO: <Company name>  (signed by File Verified)

Product:
TODO: <Product name>

Description:
Chrome_Updater

Version:
1.0.0.1

MD5:
5bd37aabaa236a17d90cde2bbe1ba916

SHA-1:
47b075d104ff3080f7dc199859ca6a632dc1534c

SHA-256:
55e8287e16196331c752a3fd1f0da076aadf65ae239419949956601e581a778a

Scanner detections:
29 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/23/2024 3:41:10 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.1014752
6414176

Agnitum Outpost
PUA.InstallMetrix
7.1.1

AhnLab V3 Security
PUP/Win32.InstallMonster
2015.01.10

Avira AntiVirus
Adware/InstallMonster.deih.13
7.11.183.220

avast!
Win32:Rootkit-gen [Rtk]
2014.9-150210

AVG
Adware Generic6.JTV
2014.0.4257

Bitdefender
Dropped:Application.Generic.936355
1.0.20.205

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.Installmetrix-6
0.98/20051

Comodo Security
TrojWare.Win32.Yakes.UARE
20995

Dr.Web
Trojan.Domaiq.16
9.0.1.05190

Emsisoft Anti-Malware
Application.Generic.1014752
9.0.0.4799

ESET NOD32
Win32/Adware.InstallMetrix.I application
7.0.302.0

F-Prot
W32/A-215008ab
v6.4.7.1.166

F-Secure
Riskware.Application.Generic.1014752
5.13.68

G Data
Dropped:Application.Generic.936355
15.2.24

IKARUS anti.virus
PUA.InstallMetrix
t3scan.1.8.3.0

K7 AntiVirus
Adware
13.185.13943

Kaspersky
not-a-virus:AdWare.Win32.InstallMetrix
15.0.0.543

MicroWorld eScan
Dropped:Application.Generic.936355
16.0.0.123

NANO AntiVirus
Riskware.Win32.InstallMonster.dhazif
0.28.6.62995

Norman
Dropped:Application.Generic.936355
11.20150210

nProtect
Trojan-Clicker/W32.InstallMetrix.1036416
15.01.02.01

Panda Antivirus
Trj/Genetic.gen
15.02.10.01

Reason Heuristics
PUP.InstallMetrix
15.2.10.13

Sophos
PUA 'Install Metrix'
5.09

Vba32 AntiVirus
AdWare.InstallMonster
3.12.26.3

VIPRE Antivirus
Threat.4150696
34232

Zillya! Antivirus
Adware.InstallMonster.Win32.42
2.0.0.1977

File size:
1013.6 KB (1,037,952 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2014

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallMetrix Software

Language:
English (United States)

Common path:
C:\users\{user}\downloads\chrome_updater.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/9/2014 7:00:00 PM

Valid to:
10/10/2015 6:59:59 PM

Subject:
CN=File Verified, OU=File Verified, O=File Verified, STREET="660 4th Street, Suite 427", L=San Francisco, S=California, PostalCode=94107, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
3218B54F8331C296189D5EA9E74030ED

File PE Metadata
Compilation timestamp:
11/22/2014 10:03:14 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:Q2Q8ROX07n/PESEa0kbtoRrkVtBzOn6TphCBj3W:iX2n/PEy0OtoRr8BzOCbk6

Entry address:
0x695A

Entry point:
E8, 50, 1B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 08, 0D, 41, 00, 89, 0D, 04, 0D, 41, 00, 89, 15, 00, 0D, 41, 00, 89, 1D, FC, 0C, 41, 00, 89, 35, F8, 0C, 41, 00, 89, 3D, F4, 0C, 41, 00, 66, 8C, 15, 20, 0D, 41, 00, 66, 8C, 0D, 14, 0D, 41, 00, 66, 8C, 1D, F0, 0C, 41, 00, 66, 8C, 05, EC, 0C, 41, 00, 66, 8C, 25, E8, 0C, 41, 00, 66, 8C, 2D, E4, 0C, 41, 00, 9C, 8F, 05, 18, 0D, 41, 00, 8B, 45, 00, A3, 0C, 0D, 41, 00, 8B, 45, 04, A3, 10, 0D, 41, 00, 8D, 45, 08, A3, 1C, 0D, 41...
 
[+]

Entropy:
7.8254  (probably packed)

Code size:
40 KB (40,960 bytes)

The file chrome_updater.exe has been seen being distributed by the following URL.

Remove chrome_updater.exe - Powered by Reason Core Security