iobit uninstaller.exe

SETUPPROCESS

This is the Solimba installer program that will bundle additional offers mostly including adware and various unwanted PC utilities. The application iobit uninstaller.exe by SETUPPROCESS has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. It is also typically executed from an Internet Explorer cache folder. While running, it connects to the Internet address cdn.solimba.com on port 80 using the HTTP protocol.
Publisher:
SETUPPROCESS  (signed and verified)

Description:
SetupManager

Version:
3.0.30.2

MD5:
383fef84e6b64a1a61a8f7cb7aae2e49

SHA-1:
5a5ca63abeb98d5d44e22f6aa9c44f79c20e5bb4

SHA-256:
58bbe3cbf95e926a3b37c49cb1d82ff8416d5a438c7af02e79ce7a166ed9286b

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/2/2024 5:31:01 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/MPress
7.1.1

ESET NOD32
Win32/FirseriaInstaller (variant)
8.9411

G Data
Win32.Application.Morstar
14.3.24

Malwarebytes
PUP.Optional.Bundler
v2014.03.07.01

Panda Antivirus
Trj/Genetic.gen
14.03.07.01

Qihoo 360 Security
HEUR/Malware.QVM18.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.SETUPPROCESS.R
14.3.7.13

Sophos
Solimba Installer
4.97

Vba32 AntiVirus
Downware.Morstar
3.12.24.3

VIPRE Antivirus
DownloadMR
26372

File size:
267.9 KB (274,288 bytes)

Product version:
3.0.30

Copyright:
Copyright ©2014

Original file name:
setup_installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\iobit uninstaller.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
11/27/2013 1:00:00 AM

Valid to:
12/1/2014 1:00:00 PM

Subject:
CN=SETUPPROCESS, O=SETUPPROCESS, L=Badalona, S=Barcelona, C=ES

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0A8ABFC7C80D0C2F0A3A89CF6139A91D

File PE Metadata
Compilation timestamp:
2/7/2014 4:46:02 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:Jr6reu56KHY7vu1H1RBGl8TVXFeZYYbFAcbeu5Z5AxTi/IrG:oCqY721HtZeYPIpPW0/SG

Entry address:
0x7C117

Entry point:
60, E8, 00, 00, 00, 00, 58, 05, 9F, 02, 00, 00, 8B, 30, 03, F0, 2B, C0, 8B, FE, 66, AD, C1, E0, 0C, 8B, C8, 50, AD, 2B, C8, 03, F1, 8B, C8, 57, 51, 49, 8A, 44, 39, 06, 88, 04, 31, 75, F6, 8B, D6, 8B, CF, E8, 5C, 00, 00, 00, 5E, 5A, 2B, C0, 89, 04, 32, B4, 10, 2B, D0, 2B, C9, 3B, CA, 73, 26, 8B, D9, AC, 41, 24, FE, 3C, E8, 75, F2, 43, 83, C1, 04, AD, 0B, C0, 78, 06, 3B, C2, 73, E5, EB, 06, 03, C3, 78, DF, 03, C2, 2B, C3, 89, 46, FC, EB, D6, E8, 00, 00, 00, 00, 5F, 81, C7, 8C, FF, FF, FF, B0, E9, AA, B8, 9B...
 
[+]

Packer / compiler:
ASPack v1.08.04

Code size:
102 KB (104,448 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to cdn.solimba.com  (95.211.6.35:80)

TCP (HTTP):
Connects to api.downloadmr.com  (95.211.39.161:80)

 
http://api.downloadmr.com/installer/8641806/launch

Remove iobit uninstaller.exe - Powered by Reason Core Security