ContentExplorer.exe

Lake Ventures LLC

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application ContentExplorer.exe by Lake Ventures has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Adknowledge Fusion installer. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘ContentExplorer’. This file is typically installed with the program ContentExplorer by Lake Ventures LLC which is a potentially unwanted software program.
Publisher:
ContentExplorer  (signed by Lake Ventures LLC)

Product:
ContentExplorer

Version:
1.0.0.0

MD5:
1ba8c6b20872163b81fd3d168c776001

SHA-1:
bab60c538924230bc856a28533d6e5a54427bba1

Scanner detections:
1 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/26/2024 1:25:48 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Startup.LakeVentures.P
14.4.9.14

File size:
432.8 KB (443,152 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © ContentExplorer 2013

Original file name:
ContentExplorer.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Application data\contentexplorer\contentexplorer.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
12/17/2013 11:22:44 PM

Valid to:
12/17/2014 11:22:44 PM

Subject:
CN=Lake Ventures LLC, O=Lake Ventures LLC, L=Aliso Viejo, S=California, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B14BBCA37F140

File PE Metadata
Compilation timestamp:
3/3/2014 10:56:44 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:ANJwBo3o+dXJuftslS3qT8WeibVHsgrUfGK9+:8wBo3DdXJjZ8ip/0

Entry address:
0x6B02E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
420.5 KB (430,592 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ContentExplorer

Command:
"C:\Documents and Settings\{user}\Application data\contentexplorer\contentexplorer.exe"


The file ContentExplorer.exe has been discovered within the following programs.

ContentExplorer  by Lake Ventures LLC
From the Terms and Conditions: "Content Explorer is ad-supported. During general internet usage on sites where Content Explorer operates, users may see additional banner, search, pop-up, pop-under, and in-text link advertisements.
ContentExplorer.net
85% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to rsvd-akamai-158.136.188.204.in-addr.arpa  (204.188.136.158:80)

TCP (HTTP):
Connects to ec2-52-70-3-92.compute-1.amazonaws.com  (52.70.3.92:80)

TCP (HTTP SSL):
Connects to a-0011.a-msedge.net  (204.79.197.213:443)

TCP (HTTP):

TCP (HTTP):
Connects to 149-210-169-43.colo.transip.net  (149.210.169.43:80)

TCP (HTTP SSL):
Connects to ipv4_1.lagg0.c120.nyc001.ix.nflxvideo.net  (108.175.43.180:443)

TCP (HTTP SSL):
Connects to col403-m.hotmail.com  (157.56.17.248:443)

TCP (HTTP SSL):
Connects to a23-211-103-175.deploy.static.akamaitechnologies.com  (23.211.103.175:443)

TCP (HTTP):
Connects to origin-home.mcafee.com  (161.69.12.12:80)

TCP (HTTP SSL):
Connects to ipv4_1.lagg0.c129.nyc001.ix.nflxvideo.net  (108.175.42.189:443)

TCP (HTTP SSL):
Connects to ipv4_1.lagg0.c123.nyc001.ix.nflxvideo.net  (108.175.42.183:443)

TCP (HTTP SSL):
Connects to ec2-52-26-64-50.us-west-2.compute.amazonaws.com  (52.26.64.50:443)

TCP (HTTP):
Connects to ec2-52-205-232-217.compute-1.amazonaws.com  (52.205.232.217:80)

TCP (HTTP SSL):
Connects to blu403-m.hotmail.com  (134.170.0.200:443)

TCP (HTTP):
Connects to a23-192-13-119.deploy.static.akamaitechnologies.com  (23.192.13.119:80)

TCP (HTTP):
Connects to 94.31.29.54.IPYX-077437-ZYO.above.net  (94.31.29.54:80)

TCP (HTTP SSL):
Connects to server-52-84-128-63.iad16.r.cloudfront.net  (52.84.128.63:443)

TCP (HTTP):
Connects to pr-bh.pbp.vip.bf1.yahoo.com  (72.30.2.182:80)

TCP (HTTP SSL):
Connects to ir1.fp.vip.bf1.yahoo.com  (98.139.180.149:443)

TCP (HTTP SSL):
Connects to ipv4_1.lagg0.c080.nyc001.ix.nflxvideo.net  (108.175.42.154:443)

Remove ContentExplorer.exe - Powered by Reason Core Security