pcduninstall.exe

Delimax Concept

This is the Solimba installer program that will bundle additional offers mostly including adware and various unwanted PC utilities. The application pcduninstall.exe by Delimax Concept has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Delimax Concept  (signed and verified)

MD5:
dab217231e381442351f999d9cbf7c38

SHA-1:
98670666d2753a3cf97e0e3d3554dd61d9402d10

SHA-256:
ec23111428dfc261d2358697509adf579091292fa7590468e680576780dc9b65

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/17/2024 7:34:23 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
2014.9-150313

AVG
Generic
2016.0.3171

herdProtect (fuzzy)
2015.6.20.5

K7 AntiVirus
Riskware
13.202.15364

Malwarebytes
PUP.Optional.Delimax
v2015.06.20.05

Reason Heuristics
PUP.Bundler.Solimba
15.3.13.23

Sophos
Solimba Installer
4.98

VIPRE Antivirus
Threat.4782980
38552

File size:
521.2 KB (533,712 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\Program Files\pcdapp\pcduninstall.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
9/24/2014 5:45:00 AM

Valid to:
9/24/2016 5:44:59 AM

Subject:
CN=Delimax Concept, O=Delimax Concept, L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
069CC4A932F0EBBF4CDE6CBB8C7AAD67

File PE Metadata
Compilation timestamp:
3/9/2015 4:41:58 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:nOJlGnuSk8q2I/IvfCImbqo1c+l+zWG0rxxPAQB:nOJlGzHkIvfADTlk6dZAe

Entry address:
0xDD3C

Entry point:
E8, F1, 53, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 30, 3D, 42, 00, E8, AE, 2B, 00, 00, E8, C2, 55, 00, 00, 0F, B7, F0, 6A, 02, E8, 84, 53, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 1F, 49, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.7260  (probably packed)

Code size:
104.5 KB (107,008 bytes)

Remove pcduninstall.exe - Powered by Reason Core Security