chrome_updater.exe

File Validated

This is the InstallMetrix bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application chrome_updater.exe by File Validated has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the InstallMetrix Software installer. With this installer, users are expecting to download Google's Chrome web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
File Validated  (signed and verified)

MD5:
2af36e11382e5b6f53b2105e15ab35ad

SHA-1:
6535e3543ce8a4e41cc5d205796e7dd9ef7b4b9e

SHA-256:
0544550be17bf02ebecdb67836fc29a5b6268aa648e2279498a453c8ddd79840

Scanner detections:
15 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 4:10:17 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Strictor.83978
5582599

Avira AntiVirus
PUA/DomaIQ.Gen4
8.3.1.6

AVG
Generic
2016.0.3107

Bitdefender
Gen:Variant.Adware.Strictor.83978
1.0.20.680

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.Domaiq.215
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Strictor.83978
10.0.0.5366

ESET NOD32
Win32/Adware.InstallMetrix (variant)
9.11638

F-Secure
Gen:Variant.Adware.Strictor
5.13.68

G Data
Gen:Variant.Adware.Strictor.83978
15.5.25

K7 AntiVirus
Adware
13.204.15934

MicroWorld eScan
Gen:Variant.Adware.Strictor.83978
16.0.0.408

NANO AntiVirus
Trojan.Script.Autoit.drhunc
0.30.24.1357

Rising Antivirus
PE:Trojan.Win32.Injector.fw!1075357566
23.00.65.15514

File size:
1.1 MB (1,144,048 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallMetrix Software

Language:
English (United Kingdom)

Common path:
C:\users\{user}\downloads\chrome_updater.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
2/26/2015 5:00:00 PM

Valid to:
2/27/2016 4:59:59 PM

Subject:
CN=File Validated, OU=File Validated, O=File Validated, L=San Francisco, S=California, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1C96D72469336B0857534EE1D7E9701D

File PE Metadata
Compilation timestamp:
4/6/2015 10:17:40 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:itb20pkaCqT5TBWgNQ7a6Q8P/tAmjcl/qe1Fytcz6Ad:vVg5tQ7a6pP/tAmAjWtg5d

Entry address:
0x25F74

Entry point:
E8, 6A, CE, 00, 00, E9, 7F, FE, FF, FF, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 58, 01, 4C, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 70, A3, 4B, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 58, 01, 4C, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00, F7, C6, 03, 00...
 
[+]

Entropy:
7.0551

Code size:
557.5 KB (570,880 bytes)

The file chrome_updater.exe has been seen being distributed by the following URL.

Remove chrome_updater.exe - Powered by Reason Core Security