nero burning rom.exe

PortalProgramas

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application nero burning rom.exe, “ Application Install ” by PortalProgramas has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Setup·process  (signed by PortalProgramas)

Description:
Application Install

Version:
3.0.30.11

MD5:
df541428b42ded8c68daf3895eceadd2

SHA-1:
2e4d0166c6bce017635cb72b4e8ea6ae92b537b3

SHA-256:
5810b464fe5f3fa9728e4918a2a717bbcdfe219115cb299099a8bc8260cea647

Scanner detections:
20 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 9:46:57 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Solimba
7.1.1

Avira AntiVirus
APPL/Firseria.5585
7.11.134.182

AVG
MalSign.Solimba
2015.0.3503

Dr.Web
Adware.Downware.2167
9.0.1.0106

ESET NOD32
Win32/FirseriaInstaller (variant)
8.9499

Fortinet FortiGate
Riskware/Morstar
4/16/2014

G Data
Win32.Application.Morstar
14.4.24

herdProtect (fuzzy)
2014.6.13.3

IKARUS anti.virus
not-a-virus:Downloader.Win32.Morstar
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.176.11784

Kaspersky
not-a-virus:Downloader.Win32.Morstar
14.0.0.4008

Malwarebytes
PUP.Optional.Solimba
v2014.04.16.11

NANO AntiVirus
Trojan.Win32.Morstar.cumkck
0.28.0.59288

Panda Antivirus
Trj/Genetic.gen
14.04.16.11

Reason Heuristics
PUP.Installer.PortalProgramas.Q
14.8.8.0

Rising Antivirus
PE:Malware.Morstar!6.149A
23.00.65.14414

Sophos
Solimba Installer
4.98

SUPERAntiSpyware
Adware.Morstar/Variant
10662

Vba32 AntiVirus
Downware.Morstar
3.12.24.3

VIPRE Antivirus
DownloadMR
27072

File size:
288.4 KB (295,328 bytes)

Product version:
3.0.30

Copyright:
Copyright © 2013·14

Original file name:
setupinstaller.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/2/2014 7:30:00 PM

Valid to:
1/3/2015 7:29:59 PM

Subject:
CN=PortalProgramas, OU=Tech, O=PortalProgramas, STREET="Balmes 1, primera planta", L=Terrassa, S=Barcelona, PostalCode=08225, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FD1E07CCAABD98839CDBE058C9F8B3E9

File PE Metadata
Compilation timestamp:
2/25/2014 12:32:37 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:/mRZ2W5Ij46YOG0G+EQ2eiAIQibh8HOlxHUbx1LqrGF:/6H67bG0lEQ2kioOlNUv2rGF

Entry address:
0xD7B9

Entry point:
E8, C8, 79, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 60, 44, 42, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 64, 44, 42, 00, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, BA, 58, 00, 00, 85, C0, 75, 06, B8, C8, 45, 42, 00, C3, 83, C0, 08, C3, E8, A7, 58, 00, 00, 85, C0, 75, 06, B8, CC, 45, 42, 00, C3, 83, C0, 0C, C3, 8B, FF, 55, 8B, EC, 56, E8, E2, FF, FF, FF, 8B, 4D, 08...
 
[+]

Code size:
111.5 KB (114,176 bytes)

The file nero burning rom.exe has been seen being distributed by the following URL.

Remove nero burning rom.exe - Powered by Reason Core Security