updater.exe

The application updater.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from de.xtecdownload.com.
MD5:
12364d267d74e84dd38e6ea83060dda4

SHA-1:
51046fdb1b6a754b864402b86ad96cb12e67f66a

SHA-256:
2967a15be7b647d9a6754f5441e993f290966f1577607ff847a4458a41750ab1

Scanner detections:
21 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 12:01:12 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.12331731
751

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
TR/StartPage.1880064
7.11.200.120

avast!
Win32:Malware-gen
2014.9-150114

AVG
Startpage
2016.0.3229

Baidu Antivirus
Trojan.Win32.StartPage
4.0.3.15114

Bitdefender
Trojan.Generic.12331731
1.0.20.70

Comodo Security
UnclassifiedMalware
20661

Emsisoft Anti-Malware
Trojan.Generic.12331731
8.15.01.14.02

ESET NOD32
Win32/StartPage.AJX
9.10991

Fortinet FortiGate
W32/StartPage.AJX!tr
1/14/2015

F-Secure
Trojan.Generic.12331731
11.2015-14-01_4

G Data
Trojan.Generic.12331731
15.1.24

IKARUS anti.virus
Trojan.Win32.StartPage
t3scan.1.8.6.0

McAfee
Artemis!12364D267D74
5600.6885

Norman
Startpage.IXQH
11.20150114

nProtect
Trojan.Generic.12331731
15.01.09.01

Rising Antivirus
PE:Trojan.Win32.Generic.17D225E4!399648228
23.00.65.15112

Trend Micro House Call
TROJ_GEN.R002C0EA315
7.2.14

Trend Micro
TROJ_GEN.R002C0EA315
10.465.14

VIPRE Antivirus
Trojan.Win32.Generic
36524

File size:
1.8 MB (1,880,064 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\microsoft\windows\start menu\programs\startup\updater.exe

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.64

CTPH (ssdeep):
49152:46D5BrJsGq5o0dzWyKRcTLOnTv+egGv73hTanui:t5B1sGq5oz3RccvcGD3hTDi

Entry address:
0x152920

Entry point:
C6, 05, 30, 39, 55, 00, 00, E8, B4, FF, FF, FF, B8, 30, C3, 5A, 00, E8, 9A, E2, EB, FF, C3, 00, 00, 00, 00, 00, 00, 00, 00, 00, FF, FF, FF, FF, 00, 00, 00, 00, FF, FF, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Code size:
1.3 MB (1,382,736 bytes)

User Start Menu Item
Name:
updater.exe


The file updater.exe has been seen being distributed by the following URL.

Remove updater.exe - Powered by Reason Core Security