visio 2010.exe

PortalProgramas

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application visio 2010.exe, “ Application Install ” by PortalProgramas has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Setup·process  (signed by PortalProgramas)

Description:
Application Install

Version:
3.0.30.11

MD5:
f4d3903117d3443d1ee275b8ada441cd

SHA-1:
20fed7b992036513d340aa3396c9df24a19c3e92

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 3:52:31 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Solimba (M)
16.7.16.21

File size:
288.4 KB (295,328 bytes)

Product version:
3.0.30

Copyright:
Copyright © 2013·14

Original file name:
setupinstaller.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\Documents and Settings\{user}\My documents\downloads\visio 2010.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/2/2014 7:00:00 PM

Valid to:
1/3/2015 6:59:59 PM

Subject:
CN=PortalProgramas, OU=Tech, O=PortalProgramas, STREET="Balmes 1, primera planta", L=Terrassa, S=Barcelona, PostalCode=08225, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FD1E07CCAABD98839CDBE058C9F8B3E9

File PE Metadata
Compilation timestamp:
2/25/2014 12:02:37 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:BmRZ2W5Ij46YOG0G+EQ2eiAIQibh8HOlxHUbx1LqrGJH:B6H67bG0lEQ2kioOlNUv2rGV

Entry address:
0xD7B9

Entry point:
E8, C8, 79, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 60, 44, 42, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 64, 44, 42, 00, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, BA, 58, 00, 00, 85, C0, 75, 06, B8, C8, 45, 42, 00, C3, 83, C0, 08, C3, E8, A7, 58, 00, 00, 85, C0, 75, 06, B8, CC, 45, 42, 00, C3, 83, C0, 0C, C3, 8B, FF, 55, 8B, EC, 56, E8, E2, FF, FF, FF, 8B, 4D, 08...
 
[+]

Code size:
111.5 KB (114,176 bytes)

The file visio 2010.exe has been seen being distributed by the following URL.

Remove visio 2010.exe - Powered by Reason Core Security