ContentExplorer.exe

Lake Ventures LLC

This is published and distributed via an Adknowledge's advertising supported (adware) software installer. The application ContentExplorer.exe by Lake Ventures has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘ContentExplorer’. This file is typically installed with the program ContentExplorer by Lake Ventures LLC which is a potentially unwanted software program.
Publisher:
ContentExplorer  (signed by Lake Ventures LLC)

Product:
ContentExplorer

Version:
1.0.0.0

MD5:
01be38e5af06d67a0baa09a7a133d8a9

SHA-1:
e5ccfd0b93ad28b9dffe7265da128aa644825323

SHA-256:
fb02841fcb3fa578832808b54c777cf33c4d6802d20409ac6c953b9bfe50ab15

Scanner detections:
1 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Analysis date:
12/26/2024 5:10:22 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Startup.LakeVentures.P
14.4.9.14

File size:
432.8 KB (443,152 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © ContentExplorer 2013

Original file name:
ContentExplorer.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\contentexplorer\contentexplorer.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
12/17/2013 5:22:44 PM

Valid to:
12/17/2014 5:22:44 PM

Subject:
CN=Lake Ventures LLC, O=Lake Ventures LLC, L=Aliso Viejo, S=California, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B14BBCA37F140

File PE Metadata
Compilation timestamp:
3/11/2014 4:39:19 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:uNB5Bo3o+dXJuftslS3qT8WeibVHsgrUfG/ok292:+5Bo3DdXJjZ8ip/0/

Entry address:
0x6B0EE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.7241

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
420.5 KB (430,592 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ContentExplorer

Command:
"C:\users\{user}\appdata\roaming\contentexplorer\contentexplorer.exe"


The file ContentExplorer.exe has been discovered within the following programs.

ContentExplorer  by Lake Ventures LLC
From the Terms and Conditions: "Content Explorer is ad-supported. During general internet usage on sites where Content Explorer operates, users may see additional banner, search, pop-up, pop-under, and in-text link advertisements.
ContentExplorer.net
85% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to snt-re4-6a.sjc.dropbox.com  (108.160.163.97:80)

TCP (HTTP):
Connects to snt-re3-10c.sjc.dropbox.com  (108.160.162.115:80)

TCP (HTTP):
Connects to sjd-rf15-7c.sjc.dropbox.com  (108.160.167.35:80)

TCP (HTTP):
Connects to sjd-rf15-6c.sjc.dropbox.com  (108.160.167.39:80)

TCP (HTTP):
Connects to sin01s17-in-f25.1e100.net  (173.194.117.121:80)

TCP (HTTP):
Connects to sin01s17-in-f15.1e100.net  (173.194.117.111:80)

TCP (HTTP):
Connects to sin01s16-in-f8.1e100.net  (173.194.117.72:80)

TCP (HTTP):
Connects to sin01s15-in-f1.1e100.net  (173.194.117.33:80)

TCP (HTTP SSL):
Connects to sa-in-f84.1e100.net  (74.125.200.84:443)

TCP (HTTP):
Connects to sa-in-f155.1e100.net  (74.125.200.155:80)

TCP (HTTP):
Connects to sa-in-f139.1e100.net  (74.125.200.139:80)

TCP (HTTP SSL):
Connects to sa-in-f113.1e100.net  (74.125.200.113:443)

TCP (HTTP SSL):
Connects to mrs04s10-in-f6.1e100.net  (173.194.32.102:443)

TCP (HTTP):
Connects to iad23s08-in-f4.1e100.net  (74.125.228.100:80)

TCP (HTTP):
Connects to iad23s08-in-f3.1e100.net  (74.125.228.99:80)

TCP (HTTP):
Connects to freedownloadmanager.org  (199.101.132.243:80)

TCP (HTTP SSL):
Connects to ee-in-f101.1e100.net  (173.194.65.101:443)

TCP (HTTP):
Connects to edge-star-shv-09-cdg2.facebook.com  (179.60.192.129:80)

TCP (HTTP SSL):
Connects to edge-star-shv-07-lhr3.facebook.com  (31.13.90.97:443)

TCP (HTTP SSL):
Connects to edge-star-mini-shv-01-iad3.facebook.com  (31.13.69.228:443)

Remove ContentExplorer.exe - Powered by Reason Core Security