mantenimiento vehiculos excel.exe

PortalProgramas

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application mantenimiento vehiculos excel.exe, “ Application Install ” by PortalProgramas has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Setup-process  (signed by PortalProgramas)

Description:
Application Install

Version:
3.1.1.0

MD5:
8a0c69f4190456d25c1438c8713936f2

SHA-1:
1536a37539580c9085d67149f4ac7b7a30175a6e

SHA-256:
235671a11e15af390c9c9035a48740c0a238fe44c3d25d0d60838bca8d8bd365

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/24/2024 10:55:53 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Firseria
7.1.1

Avira AntiVirus
Adware/Downware.skee
7.11.145.10

AVG
BundleApp
2015.0.3495

Comodo Security
Application.Win32.Agent.TE
18157

Dr.Web
Adware.Downware.2207
9.0.1.0113

ESET NOD32
Win32/FirseriaInstaller (variant)
8.9714

G Data
Win32.Application.Morstar
14.4.24

IKARUS anti.virus
not-a-virus:Downloader.Win32.Morstar
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.176.11861

Malwarebytes
PUP.Optional.Rapiddown
v2014.04.23.10

Panda Antivirus
PUP/MultiToolbar.A
14.04.23.10

Reason Heuristics
PUP.Installer.PortalProgramas.DD
14.8.8.0

Sophos
Solimba Installer
4.98

SUPERAntiSpyware
Adware.RapidDown/Variant
10647

Vba32 AntiVirus
Downware.Morstar
3.12.26.0

VIPRE Antivirus
DownloadMR
28550

File size:
293.9 KB (300,960 bytes)

Product version:
3.1.1

Copyright:
Copyright ©2013·14

Original file name:
setupinstall.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\users\{user}\downloads\mantenimiento vehiculos excel.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/2/2014 6:00:00 PM

Valid to:
1/3/2015 5:59:59 PM

Subject:
CN=PortalProgramas, OU=Tech, O=PortalProgramas, STREET="Balmes 1, primera planta", L=Terrassa, S=Barcelona, PostalCode=08225, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FD1E07CCAABD98839CDBE058C9F8B3E9

File PE Metadata
Compilation timestamp:
3/3/2014 10:33:16 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:L2XZdx5OVpwA6EGAiuuKRpBuQtv3NSjMjtG6aLlYmKF:L2p5OVO5EGAiuuKrzv3N/LaLlYmKF

Entry address:
0xE379

Entry point:
E8, C8, 79, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 60, 54, 42, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 64, 54, 42, 00, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, BA, 58, 00, 00, 85, C0, 75, 06, B8, C8, 55, 42, 00, C3, 83, C0, 08, C3, E8, A7, 58, 00, 00, 85, C0, 75, 06, B8, CC, 55, 42, 00, C3, 83, C0, 0C, C3, 8B, FF, 55, 8B, EC, 56, E8, E2, FF, FF, FF, 8B, 4D, 08...
 
[+]

Entropy:
7.2648

Code size:
114.5 KB (117,248 bytes)

The file mantenimiento vehiculos excel.exe has been seen being distributed by the following URL.

Remove mantenimiento vehiculos excel.exe - Powered by Reason Core Security