lyrics plugin for winamp.exe

lyrics-plugin-for-winamp

Solimba Aplicaciones S.L.

This is the Solimba installer program that will bundle additional offers mostly including adware and various unwanted PC utilities. The application lyrics plugin for winamp.exe by Solimba Aplicaciones S.L has been detected as adware by 29 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. The file has been seen being downloaded from d1w467en2eqqh2.cloudfront.net.
Publisher:
Solimba Aplicaciones S.L.  (signed and verified)

Product:
lyrics-plugin-for-winamp

Version:
2.2.43.0

MD5:
8dc1c7eb3696535997c3ae8640f032d6

SHA-1:
6898dd6e2817b8c0da5006f150ae5669e1eb90ab

SHA-256:
c0e4ab0e7092baf3bdb28df898efd010de01273d6458206220239b2c740f87ba

Scanner detections:
29 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/23/2024 7:12:57 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Solimba.1
855

Agnitum Outpost
Trojan.Adware
7.1.1

AhnLab V3 Security
Win-PUP/Solimba
2014.10.04

Avira AntiVirus
APPL/Solimba.Gen
7.11.176.116

avast!
Solimba-D [PUP]
140929-0

AVG
Adware AdInstaller.Q
2014.0.4037

Bitdefender
Gen:Variant.Adware.Solimba.1
1.0.20.1380

Clam AntiVirus
WIN.Adware.Solimba-3
0.98/19476

Comodo Security
Application.Win32.Solimba.a
19693

Dr.Web
Adware.Downware.798
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Solimba
14.10.03

ESET NOD32
MSIL/Solimba.H potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Solimba
10/3/2014

F-Prot
W32/Solimba.B.gen
4.6.5.141

F-Secure
Gen:Variant.Adware.Solimba.1
11.2014-03-10_6

G Data
Gen:Variant.Adware.Solimba
14.10.24

K7 AntiVirus
Unwanted-Program
13.183.13550

Kaspersky
not-a-virus:AdWare.MSIL.Solimba
15.0.0.494

Malwarebytes
PUP.BundleInstaller.SOL
v2014.10.03.10

MicroWorld eScan
Gen:Variant.Adware.Solimba.1
15.0.0.828

NANO AntiVirus
Riskware.Win32.Downware.cruvdx
0.28.2.62440

Panda Antivirus
Adware/Solimba
14.10.03.10

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
PUP.SolimbaAplicacionesSL.Y
14.10.3.7

Rising Antivirus
PE:Trojan.Win32.Generic.14BDA2DA!347972314
23.00.65.141001

Sophos
Solimba Installer
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Solimba
10322

Vba32 AntiVirus
Signed-AdWare.MSIL.SolimbaAplicacionesSL
3.12.26.3

VIPRE Antivirus
Threat.4782980
33520

File size:
176.7 KB (180,904 bytes)

Copyright:
(c) 2010 (Build:2012-10-23 15:28)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\Documents and Settings\{user}\My documents\downloads\lyrics plugin for winamp.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/16/2011 2:00:00 AM

Valid to:
5/16/2013 1:59:59 AM

Subject:
CN=Solimba Aplicaciones S.L., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Solimba Aplicaciones S.L., L=Badalona, S=Barcelona, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
450EE582E26020D5F7632F2BECC6C5BD

File PE Metadata
Compilation timestamp:
8/30/2011 5:46:24 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.21

CTPH (ssdeep):
3072:EnOn7t7XpdpCCTg/sxFgJDRdCa43boeqcVIxg/eDy3sNwDQMN1MtHk0AfHw04+:EKpdcCrTqqa4LoeBIxdDy3owDXN1MtEz

Entry address:
0x4327

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 83, 42, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 84, 42, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 84, 42, 00, 56, A3, 40, 6B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 6B, 42, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, 84, 42, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Code size:
34.5 KB (35,328 bytes)

The file lyrics plugin for winamp.exe has been seen being distributed by the following URL.

Remove lyrics plugin for winamp.exe - Powered by Reason Core Security