irfanview.exe

Delimax Concept s.l.

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application irfanview.exe by Delimax Concept s.l has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Delimax Concept s.l.  (signed and verified)

MD5:
eaf14976410c14f8c30d372ede1bfaec

SHA-1:
ea86c40eeb1a721d169237ec10e281048bef5ecb

SHA-256:
7f59595b48b7811e76c28a7c8fed552001da77fffc1b204bd9cca678e49da4f5

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/27/2024 2:46:28 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Solimba (M)
17.2.23.16

File size:
562.1 KB (575,560 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\users\{user}\downloads\irfanview.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
9/24/2014 5:17:54 PM

Valid to:
9/24/2016 5:17:54 PM

Subject:
CN=Delimax Concept s.l., O=Delimax Concept s.l., L=Barcelona, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121212688B372352B5E314485FB66EA867C

File PE Metadata
Compilation timestamp:
12/9/2014 10:19:47 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0xD44C

Entry point:
E8, AF, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 00, 60, 42, 00, E8, FE, 15, 00, 00, E8, 80, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 42, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 0B, 65, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
111 KB (113,664 bytes)

The file irfanview.exe has been seen being distributed by the following URL.

http://it.win-install.info/irfanview/download/.../846

Remove irfanview.exe - Powered by Reason Core Security