winrar.exe

The application winrar.exe has been detected as a potentially unwanted program by 7 anti-malware scanners. This is a setup program which is used to install the application. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. The file has been seen being downloaded from cyanfile.com.
MD5:
45bd7c8baa95b79fd62ff0771aae1017

SHA-1:
aa259cd70e22bb20084e7ca27212cde93ba7bab6

SHA-256:
0168d64b9b0a20c4a201be2a56e4b2e6f01eedc194e27746e0f1d9510ab96664

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
Uses the Solimba installer to bundle adware offers.

Analysis date:
12/26/2024 2:25:06 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
MSIL:Solimba-Z [PUP]
160518-2

AVG
Adware BundleApp_r.AV
2015.0.4568

Dr.Web
Adware.Downware.8808
9.0.1.05190

ESET NOD32
MSIL/Solimba.AH potentially unwanted application
8.0.319.0

Kaspersky
not-a-virus:Downloader.Win32.Morstar
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.223.1075.0

Reason Heuristics
Adware.Bundler (M)
16.6.9.12

File size:
384.6 KB (393,780 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\winrar.exe

File PE Metadata
Compilation timestamp:
10/20/2014 12:42:05 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:/P/uS5fAsKTCvFN5lQ2EAQCVQRdkuG+66fBP5X:/P/uStKTE57HSjj9/

Entry address:
0xDEDC

Entry point:
E8, AE, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, F8, 6F, 42, 00, E8, FE, 15, 00, 00, E8, 7F, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 41, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 0A, 65, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
113.5 KB (116,224 bytes)

The file winrar.exe has been seen being distributed by the following URL.

Remove winrar.exe - Powered by Reason Core Security