updater.exe

Creative Island Media, LLC

Part of the branded Injekt adware package, the updater mechanism is an auto-starting program that is desigend to update the web browser extensions and protect the executables ChromeHelper, FirefoxHelper and IeHelper so that these programs can inject advertisments and generate popups in the user's web browser. The application updater.exe by Creative Island Media has been detected as adware by 22 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Updater’. This file is typically installed with the program Updater by Creative Island Media, LLC which is a potentially unwanted software program.
Publisher:
Updater  (signed by Creative Island Media, LLC)

Product:
Updater

Description:
Updater service

Version:
1, 0, 0, 1

MD5:
02c64a253f1ee84663510a7fc93f5b93

SHA-1:
e04ffeb978ecfe7e4df98204da8702df4fd966ab

SHA-256:
3b2265059afa83b07480a9ee780d60cfa059798a1b109070470ed66ffb4f8e8d

Scanner detections:
22 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
12/25/2024 12:12:16 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.NUE
1126

Avira AntiVirus
TR/Trash.Gen
7.11.30.172

avast!
Win32:TubeDim-A [PUP]
2014.9-140215

Bitdefender
Adware.Agent.NUE
1.0.20.25

Bkav FE
W32.Clod4a8.Trojan
1.3.0.4613

Boost by Reason
Optional.Startup.CreativeIslandMedia.H
188838

Dr.Web
Adware.Plugin.130
9.0.1.0355

Emsisoft Anti-Malware
Adware.Agent.NUE
8.13.12.24.02

F-Secure
Adware.Agent.NUE
11.2013-24-12_3

G Data
Win32.Application.TubeDimmer
13.12.22

IKARUS anti.virus
AdWare.Agent
t3scan.2.2.29

Malwarebytes
PUP.Optional.TubeDimmer
v2013.12.21.03

McAfee
Artemis!A5F634DAE5C0
5600.7203

MicroWorld eScan
Adware.Agent.NUE
15.0.0.15

Norman
Malware
11.20140807

nProtect
Adware.Agent.NUE
14.02.02.01

Reason Heuristics
PUP.Startup.CreativeIslandMedia.H
14.8.7.20

Sophos
Search Donkey
4.97

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10435

Trend Micro House Call
TROJ_GEN.F47V1106
7.2.355

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

VIPRE Antivirus
SearchDonkey
23956

File size:
474.9 KB (486,264 bytes)

Product version:
1, 0, 0, 1

Original file name:
updater.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\updater\updater.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/20/2013 9:00:00 PM

Valid to:
5/21/2014 8:59:59 PM

Subject:
CN="Creative Island Media, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Creative Island Media, LLC", L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
68F23F4D2767F6491DEA9186F2E5CB89

File PE Metadata
Compilation timestamp:
12/18/2013 7:46:12 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:/hKajpaatC3n5HRd7PfWsx/AORL0VNnD+70iLTx9csmrJeFbI:/gypaatCpHRJPfWARgDfiPx1mteFbI

Entry address:
0x38792

Entry point:
E8, 59, D2, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, 3A, FE, FF, FF, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, 24, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, 3C, F5, 40, 7C, 46, 00, 00, 75, 13, 56, E8, 71, 00, 00, 00, 59, 85, C0, 75, 08, 6A, 11, E8, 42, 5B, 00, 00, 59, FF, 34, F5, 40, 7C, 46, 00, FF, 15, 88, 50, 45, 00, 5E, 5D, C3, 56, 57, BE, 40, 7C, 46, 00, 8B, FE, 53, 8B, 1F, 85, DB, 74, 17, 83, 7F...
 
[+]

Code size:
332.5 KB (340,480 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Updater

Command:
C:\ProgramData\updater\updater.exe


Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Updater

Command:
C:\ProgramData\updater\updater.exe


The file updater.exe has been discovered within the following programs.

Updater  by Creative Island Media, LLC
This is the updater program installed with the company's TubeDimmer software which is typically installed through a bundled offer and is potentially unwanted.
www.injekt.com
82% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-52-42-90-80.us-west-2.compute.amazonaws.com  (52.42.90.80:80)

TCP (HTTP):
Connects to ec2-54-186-84-255.us-west-2.compute.amazonaws.com  (54.186.84.255:80)

TCP (HTTP):
Connects to server-52-84-174-62.gru50.r.cloudfront.net  (52.84.174.62:80)

TCP (HTTP):
Connects to server-54-230-206-146.atl50.r.cloudfront.net  (54.230.206.146:80)

TCP (HTTP):
Connects to server-54-192-203-129.fra50.r.cloudfront.net  (54.192.203.129:80)

TCP (HTTP):
Connects to ec2-52-32-118-15.us-west-2.compute.amazonaws.com  (52.32.118.15:80)

TCP (HTTP):
Connects to ec2-54-218-62-24.us-west-2.compute.amazonaws.com  (54.218.62.24:80)

TCP (HTTP):
Connects to server-52-85-221-224.cdg50.r.cloudfront.net  (52.85.221.224:80)

TCP (HTTP):
Connects to ec2-54-213-104-242.us-west-2.compute.amazonaws.com  (54.213.104.242:80)

TCP (HTTP):
Connects to server-54-230-59-67.gru1.r.cloudfront.net  (54.230.59.67:80)

TCP (HTTP):
Connects to server-54-230-59-54.gru1.r.cloudfront.net  (54.230.59.54:80)

TCP (HTTP):
Connects to server-54-230-187-192.cdg51.r.cloudfront.net  (54.230.187.192:80)

TCP (HTTP):
Connects to server-54-230-141-182.sfo5.r.cloudfront.net  (54.230.141.182:80)

TCP (HTTP):
Connects to server-54-192-230-53.waw50.r.cloudfront.net  (54.192.230.53:80)

TCP (HTTP):
Connects to server-54-192-203-244.fra50.r.cloudfront.net  (54.192.203.244:80)

TCP (HTTP):
Connects to server-54-192-203-220.fra50.r.cloudfront.net  (54.192.203.220:80)

TCP (HTTP):
Connects to server-54-192-203-201.fra50.r.cloudfront.net  (54.192.203.201:80)

TCP (HTTP):
Connects to server-52-85-83-20.lax1.r.cloudfront.net  (52.85.83.20:80)

TCP (HTTP):
Connects to server-52-85-77-95.lax3.r.cloudfront.net  (52.85.77.95:80)

TCP (HTTP):
Connects to server-52-85-221-215.cdg50.r.cloudfront.net  (52.85.221.215:80)

Remove updater.exe - Powered by Reason Core Security