updater.exe

WebAppTech Coding LLC

Part of the branded Injekt adware package, the updater mechanism is an auto-starting program that is desigend to update the web browser extensions and protect the executables ChromeHelper, FirefoxHelper and IeHelper so that these programs can inject advertisments and generate popups in the user's web browser. The application updater.exe by WebAppTech Coding has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Updater’.
Publisher:
Updater  (signed by WebAppTech Coding LLC)

Product:
Updater

Version:
1, 0, 0, 1

MD5:
19fe3f66b66d007ccb51a595b59d7654

SHA-1:
0d685c9cdd8d452b1508d533eac5672c92f2975b

SHA-256:
e471556ba6eb9b54b8c236570d17a650a4372cb555181e4b405be22317d530ed

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
11/23/2024 11:37:15 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt (M)
16.12.31.7

File size:
178.1 KB (182,408 bytes)

Product version:
1, 0, 0, 1

Original file name:
updater.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\common files\updater\updater.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/15/2013 7:00:00 PM

Valid to:
1/16/2014 6:59:59 PM

Subject:
CN=WebAppTech Coding LLC, O=WebAppTech Coding LLC, STREET="2885 Sanford Ave SW #18716", L=Grandville, S=MI, PostalCode=49418, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00ED976277604B937F55FA8DF427C5B534

File PE Metadata
Compilation timestamp:
4/9/2013 1:43:17 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0xE207

Entry point:
E8, 0C, 5A, 00, 00, E9, 89, FE, FF, FF, 6A, 0C, 68, 48, F5, 41, 00, E8, 23, 24, 00, 00, 6A, 0E, E8, 09, 5C, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, 8C, 2A, 42, 00, BA, 88, 2A, 42, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, 1B, F1, FF, FF, 59, FF, 76, 04, E8, 12, F1, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, 12, 24, 00, 00, C3, 8B, D0, EB, C5, 6A, 0E, E8, D5, 5A, 00, 00, 59, C3, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
6.4540

Code size:
103.5 KB (105,984 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Updater

Command:
C:\Program Files\common files\updater\updater.exe


Remove updater.exe - Powered by Reason Core Security