visual boy advance.exe

Firseria

The setup program uses the Firseria/Solimba AppInstaller (DownloadMR) which is a monetization download manager that bundles additional adware offers, typically by wrapping legitimate applications. The application visual boy advance.exe by Firseria has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
setupprocess   (signed by Firseria)

Description:
Setup Manager

Version:
3.0.30.6

MD5:
52c95613080f20b8e418c17fdd35ddac

SHA-1:
4cbd1c8ceeed6161bef479490c22a682a6b88461

SHA-256:
0efaaf4876055986f337f3350fb8ec2fd01dc7f2c5a1d5569e6925d99a01e60b

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/23/2024 11:04:44 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Firseria
7.1.1

Avira AntiVirus
APPL/Firseria.fvt
7.11.138.122

avast!
Win32:PUP-gen [PUP]
2014.9-140323

AVG
MalSign.Solimba
2015.0.3526

Comodo Security
Application.Win32.FirseriaInstaller.GTV
17979

Dr.Web
Adware.Downware.2174
9.0.1.082

ESET NOD32
Win32/FirseriaInstaller (variant)
8.9578

Malwarebytes
Trojan.Agent
v2014.03.23.01

Panda Antivirus
Suspicious file
14.03.23.01

Reason Heuristics
PUP.Installer.Firseria.Z
14.8.7.17

Sophos
Solimba Installer
4.98

Vba32 AntiVirus
Downware.Morstar
3.12.24.3

VIPRE Antivirus
DownloadMR
27668

File size:
270.7 KB (277,224 bytes)

Product version:
3.0.30

Copyright:
Copyright©2014

Original file name:
installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\visual%20boy%20advance.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
11/11/2013 10:34:44 AM

Valid to:
11/12/2014 10:34:44 AM

Subject:
E=support@solimba.com, CN=Firseria, O=Firseria, L=Badalona, S=Barcelona, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112130C3B28D7C9C29B8B07321EF3F8A1462

File PE Metadata
Compilation timestamp:
2/10/2014 6:34:59 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:KSVFVe91EZ1ypY+186MWWxBRXp5IPRdjtHt0KjHAc+gr:KSV3e91fY+6XWOjXpUtHt0Jgr

Entry address:
0x81117

Entry point:
60, E8, 00, 00, 00, 00, 58, 05, 9F, 02, 00, 00, 8B, 30, 03, F0, 2B, C0, 8B, FE, 66, AD, C1, E0, 0C, 8B, C8, 50, AD, 2B, C8, 03, F1, 8B, C8, 57, 51, 49, 8A, 44, 39, 06, 88, 04, 31, 75, F6, 8B, D6, 8B, CF, E8, 5C, 00, 00, 00, 5E, 5A, 2B, C0, 89, 04, 32, B4, 10, 2B, D0, 2B, C9, 3B, CA, 73, 26, 8B, D9, AC, 41, 24, FE, 3C, E8, 75, F2, 43, 83, C1, 04, AD, 0B, C0, 78, 06, 3B, C2, 73, E5, EB, 06, 03, C3, 78, DF, 03, C2, 2B, C3, 89, 46, FC, EB, D6, E8, 00, 00, 00, 00, 5F, 81, C7, 8C, FF, FF, FF, B0, E9, AA, B8, 9B...
 
[+]

Entropy:
7.6541

Packer / compiler:
ASPack v1.08.04

Code size:
98.5 KB (100,864 bytes)

Remove visual boy advance.exe - Powered by Reason Core Security