hp mediasmart webcam software.exe

Prelasan Developments s.l.

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application hp mediasmart webcam software.exe by Prelasan Developments s.l has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Prelasan Developments s.l.  (signed and verified)

MD5:
ea84f3a1f34790d1a764dbc6d4049f6e

SHA-1:
6e9737e6558c3714ac1fbd3fa7a86900c94f65b0

SHA-256:
9db2800ae894245c87ac530b5d358a037d996e0ae310fbaa7711ccbdb5e543be

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/26/2024 2:41:32 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Solimba.Prelasan (M)
16.6.26.2

File size:
562.1 KB (575,568 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\users\{user}\downloads\hp mediasmart webcam software.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
9/24/2014 6:07:57 PM

Valid to:
9/24/2016 6:07:57 PM

Subject:
CN=Prelasan Developments s.l., O=Prelasan Developments s.l., L=Barcelona, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121FE86E799E134BB6B2BBD0E554BFB2C1D

File PE Metadata
Compilation timestamp:
12/9/2014 10:16:08 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:3b/YqJsiTkpSODk4OPgWkf+g+vQB45FK7/Mb3evjH3SIGW4W6CIn24hbt:3b/Y3iTyzk5PgWwh4rinb31z6CIbt

Entry address:
0xD44C

Entry point:
E8, AF, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 20, 60, 42, 00, E8, FE, 15, 00, 00, E8, 80, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 42, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 0B, 65, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
111 KB (113,664 bytes)

The file hp mediasmart webcam software.exe has been seen being distributed by the following URL.

Remove hp mediasmart webcam software.exe - Powered by Reason Core Security