java.exe

Internal Setup

Condestil Developments s.l.

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application java.exe, “Configuration Process” by Condestil Developments s.l has been detected as adware by 30 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
The Apps Path  (signed by Condestil Developments s.l.)

Product:
Internal Setup

Description:
Configuration Process

Version:
3,1,18,3

MD5:
262ec053be5c82c7ab460a19b2300b47

SHA-1:
2365d4f9823657885ead456e06ffec0ddafe10ca

SHA-256:
8f8467094537b72111a22d81570b20bbd34804db30b6ecea31abf2c0b65538f2

Scanner detections:
30 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
2/25/2025 6:34:34 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Firseria.T
365

Agnitum Outpost
PUA.Firseria
7.1.1

AhnLab V3 Security
PUP/Win32.Firseria
2014.12.11

Avira AntiVirus
APPL/FirseriaM.A.2
7.11.194.62

avast!
Win32:Malware-gen
2014.9-160204

AVG
Adware BundleApp
2017.0.2843

Bitdefender
Application.Bundler.Firseria.T
1.0.20.175

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Trojan.Agent-755856
0.98/20565

Comodo Security
Application.Win32.Solimba.KUY
18995

Dr.Web
Trojan.MulDrop5.34679
9.0.1.035

Emsisoft Anti-Malware
Application.Bundler.Firseria.T
8.16.02.04.12

ESET NOD32
Win32/FirseriaInstaller.M potentially unwanted application
10.7.0.302.0

F-Prot
W32/A-7a47ae63
v6.4.7.1.166

F-Secure
Riskware.Application.Bundler.Firseria
11.2016-04-02_5

G Data
Application.Bundler.Firseria
16.2.24

IKARUS anti.virus
not-a-virus:AdWare.Fiseria
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.186.14295

Malwarebytes
PUP.Optional.Solimba
v2016.02.04.12

MicroWorld eScan
Application.Bundler.Firseria.T
17.0.0.105

Norman
Application.Bundler.Firseria.T
11.20160204

Panda Antivirus
Trj/Genetic.gen
16.02.04.12

Qihoo 360 Security
Malware.QVM18.Gen
1.0.0.1015

Quick Heal
PUA.Condestild.Gen
2.16.14.00

Reason Heuristics
PUP.Solimba.CondestilDevelopments.Installer (M)
16.2.4.12

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.16202

Sophos
PUA 'Solimba Installer'
5.15

Vba32 AntiVirus
Downware.Morstar
3.12.26.3

VIPRE Antivirus
Threat.4150696
35418

Zillya! Antivirus
Backdoor.PePatch.Win32.39331
2.0.0.2003

File size:
414.7 KB (424,648 bytes)

Product version:
3.1.20

Copyright:
Reserved © 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\java.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/24/2014 9:00:00 PM

Valid to:
7/24/2016 8:59:59 PM

Subject:
CN=Condestil Developments s.l., O=Condestil Developments s.l., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
43F850AA43DAD92FF6603BEB72F415DD

File PE Metadata
Compilation timestamp:
7/26/2014 6:06:32 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:C4W8/VUlVGRwfpQb5kP3NZVn9Mb2yOVhatb3uaNz5g7vT2XbSrZbdu6YgTmavAc9:7W8RR6PYiyYa53um5g7vT2+xfmavz9

Entry address:
0x840A4

Entry point:
60, E8, 00, 00, 00, 00, 58, 05, 5A, 0B, 00, 00, 8B, 30, 03, F0, 2B, C0, 8B, FE, 66, AD, C1, E0, 0C, 8B, C8, 50, AD, 2B, C8, 03, F1, 8B, C8, 57, 51, 49, 8A, 44, 39, 06, 88, 04, 31, 75, F6, 2B, C0, AC, 8B, C8, 80, E1, F0, 24, 0F, C1, E1, 0C, 8A, E8, AC, 0B, C8, 51, 02, CD, BD, 00, FD, FF, FF, D3, E5, 59, 58, 8B, DC, 8D, A4, 6C, 90, F1, FF, FF, 51, 2B, C9, 51, 51, 8B, CC, 51, 66, 8B, 17, C1, E2, 0C, 52, 57, 83, C1, 04, 51, 50, 83, C1, 04, 56, 51, E8, 5E, 00, 00, 00, 8B, E3, 5E, 5A, 2B, C0, 89, 04, 32, B4, 10...
 
[+]

Packer / compiler:
ASPack v1.08.04

Code size:
121 KB (123,904 bytes)

The file java.exe has been seen being distributed by the following URL.

Remove java.exe - Powered by Reason Core Security