contentexploreruninstall.exe

Installer

Application Genius, LLC

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application contentexploreruninstall.exe by Application Genius has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Adknowledge Fusion installer. This is the uninstaller utility registered in the Windows Control Panel for the program ContentExplorer by ContentExplorer. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
Application Genius, LLC  (signed and verified)

Product:
Installer

Version:
1.0.0.0

MD5:
77f3e0e7af02931bb777f1f109255ef7

SHA-1:
5ea76d310f7c171a0b9537b7cc01b0074b6d76f7

SHA-256:
61dcb70d2ee3fb1e8d18089bdcef14baa1c85b9194e32686da083858e7114506

Scanner detections:
1 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/25/2024 9:34:31 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Adknowledge (M)
17.3.15.6

File size:
900.6 KB (922,184 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
ContentExplorer2Install.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\contentexplorer\contentexploreruninstall.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
12/30/2014 6:32:38 PM

Valid to:
12/29/2016 3:07:38 PM

Subject:
CN="Application Genius, LLC", O="Application Genius, LLC", L=Walnut, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
629B575CD8F3186B

File PE Metadata
Compilation timestamp:
3/7/2015 6:30:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0xDF7CE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 14, 11, 00, 80, 10, 00, 00, 00, 64, 11, 00, 80, 18, 00, 00, 00, 88, 14, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 02, 00, 00, 00, 48, 00, 00, 80, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9637

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
886 KB (907,264 bytes)

Program Uninstaller
Program name:
ContentExplorer

Display publisher:
ContentExplorer

Display version:
8.4

Uninstall string:
C:\users\{user}\appdata\roaming\contentexplorer\contentexploreruninstall.exe -uninstall


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove contentexploreruninstall.exe - Powered by Reason Core Security