ContentExplorer.exe

Lake Ventures LLC

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application ContentExplorer.exe by Lake Ventures has been detected as adware by 3 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. This executable runs as a local area network (LAN) Internet proxy server listening on port 53443 and has the ability to intercept and modify all inbound and outbound Internet traffic on the local host. This file is typically installed with the program ContentExplorer by Lake Ventures LLC which is a potentially unwanted software program.
Publisher:
ContentExplorer  (signed by Lake Ventures LLC)

Product:
ContentExplorer

Version:
8.0

MD5:
9f1533c33a28e2cbef1758f23e8601f7

SHA-1:
5cf597d017f6a3597be1eecab9c1077d8806cd6a

SHA-256:
5079a4ffe7431b74689f8be4a6d60b2eb0281a10b563487774633297a83040a7

Scanner detections:
3 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
2/25/2025 8:42:50 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.MSIL.Gen
7.11.141.68

Reason Heuristics
PUP.LakeVentures.P
14.8.22.12

File size:
2.3 MB (2,429,680 bytes)

Product version:
8.0

Copyright:
Copyright © ContentExplorer 2014

Original file name:
ContentExplorer.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\contentexplorer\contentexplorer.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
12/17/2013 2:22:44 PM

Valid to:
12/17/2014 2:22:44 PM

Subject:
CN=Lake Ventures LLC, O=Lake Ventures LLC, L=Aliso Viejo, S=California, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B14BBCA37F140

File PE Metadata
Compilation timestamp:
7/6/2014 11:00:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:+xizjPaP5ldg5XH17jtkHs4AmQmTDx8EBj2aGTj/e:FOg5F7jtGfAmQY8Lad

Entry address:
0x2500A2

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.7829

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.3 MB (2,417,152 bytes)

Local Proxy Server
Proxy for:
Internet Settings

Local host address:
http://127.0.0.1:53443/

Local host port:
53443

Default credentials:
No


The file ContentExplorer.exe has been discovered within the following programs.

ContentExplorer  by Lake Ventures LLC
From the Terms and Conditions: "Content Explorer is ad-supported. During general internet usage on sites where Content Explorer operates, users may see additional banner, search, pop-up, pop-under, and in-text link advertisements.
ContentExplorer.net
85% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-52-84-174-229.gru50.r.cloudfront.net  (52.84.174.229:80)

TCP (HTTP):
Connects to s3-1-w.amazonaws.com  (54.231.115.43:80)

TCP (HTTP):
Connects to rio01s23-in-f16.1e100.net  (172.217.30.16:80)

TCP (HTTP SSL):
Connects to rio01s23-in-f14.1e100.net  (172.217.30.14:443)

TCP (HTTP SSL):
Connects to rio01s22-in-f226.1e100.net  (216.58.202.226:443)

TCP (HTTP SSL):
Connects to rio01s22-in-f14.1e100.net  (216.58.202.238:443)

TCP (HTTP SSL):
Connects to rio01s21-in-f78.1e100.net  (172.217.29.78:443)

TCP (HTTP SSL):
Connects to rio01s21-in-f13.1e100.net  (172.217.29.77:443)

TCP (HTTP SSL):
Connects to rio01s20-in-f14.1e100.net  (172.217.29.46:443)

TCP (HTTP SSL):
Connects to rio01s16-in-f98.1e100.net  (216.58.222.98:443)

TCP (HTTP SSL):
Connects to rio01s15-in-f78.1e100.net  (216.58.222.78:443)

TCP (HTTP SSL):
Connects to rio01s15-in-f65.1e100.net  (216.58.222.65:443)

TCP (HTTP):
Connects to porta42.akamai.as28624.oops.net.br  (201.54.172.42:80)

TCP (HTTP SSL):
Connects to porta142.carie.as28624.oops.net.br  (201.54.166.142:443)

TCP (HTTP SSL):
Connects to porta141.carie.as28624.oops.net.br  (201.54.166.141:443)

TCP (HTTP SSL):
Connects to porta140.carie.as28624.oops.net.br  (201.54.166.140:443)

TCP (HTTP):
Connects to ec2-54-94-188-131.sa-east-1.compute.amazonaws.com  (54.94.188.131:80)

TCP (HTTP SSL):
Connects to ec2-52-3-205-41.compute-1.amazonaws.com  (52.3.205.41:443)

TCP (HTTP):
Connects to ec2-50-17-220-153.compute-1.amazonaws.com  (50.17.220.153:80)

TCP (HTTP):
Connects to ec2-184-73-154-217.compute-1.amazonaws.com  (184.73.154.217:80)

Remove ContentExplorer.exe - Powered by Reason Core Security