firefox_updater.exe

File Validated

This is the InstallMetrix bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application firefox_updater.exe by File Validated has been detected as adware by 18 anti-malware scanners. The program is a setup application that uses the InstallMetrix Software installer. With this installer, users are expecting to download the free Mozilla Firefox web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
File Validated  (signed and verified)

MD5:
6a4067db90b04042f92cf5d8a6b1b1ad

SHA-1:
ddd991dd0d0451ab8f8cf1738fb334ac63aa30dd

SHA-256:
46c71e2e20edaeb5eb5aa9339539af22fdbcfe9e49c4e9fd87d52db32f4f4f7d

Scanner detections:
18 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
1/14/2025 12:33:11 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Strictor.83978
5751583

Avira AntiVirus
PUA/DomaIQ.Gen4
8.3.1.6

Arcabit
Trojan.Adware.Strictor.D1480A
1.0.0.425

AVG
Generic
2016.0.3081

Bitdefender
Gen:Variant.Adware.Strictor.83978
1.0.20.810

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.InstallMetrix.LQL
22414

Dr.Web
Trojan.Domaiq.215
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Strictor.83978
10.0.0.5366

ESET NOD32
Win32/Adware.InstallMetrix.L application
7.0.302.0

F-Prot
W32/Strictor.AG.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Strictor
5.14.151

G Data
Gen:Variant.Adware.Strictor.83978
15.6.25

K7 AntiVirus
Adware
13.205.16216

MicroWorld eScan
Gen:Variant.Adware.Strictor.83978
16.0.0.486

NANO AntiVirus
Trojan.Script.Autoit.drhunc
0.30.24.2086

Norman
Gen:Variant.Adware.Strictor.83978
02.06.2015 14:23:46

Reason Heuristics
PUP.InstallMetrix.FileValidated
15.6.11.11

File size:
1.1 MB (1,146,608 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallMetrix Software

Language:
English (United Kingdom)

Common path:
C:\users\{user}\downloads\firefox_updater.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
2/26/2015 7:00:00 PM

Valid to:
2/27/2016 6:59:59 PM

Subject:
CN=File Validated, OU=File Validated, O=File Validated, L=San Francisco, S=California, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1C96D72469336B0857534EE1D7E9701D

File PE Metadata
Compilation timestamp:
4/22/2015 6:31:55 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:Vtb20pkaCqT5TBWgNQ7aNQ8P/tvmjcl/qe1Fyyd46AC:GVg5tQ7aNpP/tvmAjWyC5C

Entry address:
0x25F74

Entry point:
E8, 6A, CE, 00, 00, E9, 7F, FE, FF, FF, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 58, 01, 4C, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 70, A3, 4B, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 58, 01, 4C, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00, F7, C6, 03, 00...
 
[+]

Entropy:
7.0585

Code size:
557.5 KB (570,880 bytes)

Remove firefox_updater.exe - Powered by Reason Core Security