solimba uninstaller.exe

Delimax Concept

This is the Solimba installer program that will bundle additional offers mostly including adware and various unwanted PC utilities. The application solimba uninstaller.exe by Delimax Concept has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from us-cdn.windapp.net and multiple other hosts.
Publisher:
Delimax Concept  (signed and verified)

MD5:
88fde8c004e7944859a296cd697c8b1f

SHA-1:
d2b1b09d9ffc07e7a98b95e16b0e2f73289e0f5c

SHA-256:
07ad9f575746d364516e4590543e445a178abe9040a6d2ff413c240e504f27c6

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/25/2024 4:21:57 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
2014.9-150316

AVG
Generic
2016.0.3168

herdProtect (fuzzy)
2015.6.22.12

K7 AntiVirus
Riskware
13.202.15364

Malwarebytes
PUP.Optional.Delimax
v2015.06.22.12

Reason Heuristics
PUP.Bundler.Solimba
15.3.16.14

Sophos
Solimba Installer
4.98

VIPRE Antivirus
Threat.4782980
38552

File size:
521.2 KB (533,712 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\solimba uninstaller.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
9/24/2014 1:00:00 AM

Valid to:
9/24/2016 12:59:59 AM

Subject:
CN=Delimax Concept, O=Delimax Concept, L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
069CC4A932F0EBBF4CDE6CBB8C7AAD67

File PE Metadata
Compilation timestamp:
3/9/2015 10:56:58 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:nOJlGnuSk8q2I/IvfCImbqo1c+l+zWG0rxxPAQ0z:nOJlGzHkIvfADTlk6dZAr

Entry address:
0xDD3C

Entry point:
E8, F1, 53, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 30, 3D, 42, 00, E8, AE, 2B, 00, 00, E8, C2, 55, 00, 00, 0F, B7, F0, 6A, 02, E8, 84, 53, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 1F, 49, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.7260  (probably packed)

Code size:
104.5 KB (107,008 bytes)

The file solimba uninstaller.exe has been seen being distributed by the following 3 URLs.

http://us-cdn.windapp.net/external/solimba/us/APC111/2015_03_16/.../Solimba Uninstaller.exe

Remove solimba uninstaller.exe - Powered by Reason Core Security