pcmark 7 1.40.exe

SETUPPROCESS

This is the Solimba installer program that will bundle additional offers mostly including adware and various unwanted PC utilities. The application pcmark 7 1.40.exe by SETUPPROCESS has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. While running, it connects to the Internet address cdn.solimba.com on port 80 using the HTTP protocol.
Publisher:
Rapiddown  (signed by SETUPPROCESS)

Description:
Setup Manager

Version:
1.0.0.40

MD5:
c07f855170154f051da873c982241567

SHA-1:
11d6597c608f6ae91aac8fdc428a3e1c2aab4a47

SHA-256:
9d1b3881bc346ba4c571ed64501593c23121e1974caf071f70584251c1a2f2f4

Scanner detections:
19 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 5:16:31 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Downloader
7.1.1

AhnLab V3 Security
PUP/Win32.Rapiddown
14.04.23

Avira AntiVirus
APPL/FirInstaller.B
7.11.145.12

avast!
Win32:Adware-gen [Adw]
2014.9-140423

AVG
Luhe.Fiha.A
2015.0.3495

Comodo Security
Application.Win32.Bechiro.BDC
18157

Dr.Web
Trojan.DownLoader11.3502
9.0.1.0113

ESET NOD32
Win32/FirseriaInstaller (variant)
8.9714

Fortinet FortiGate
Adware/Firseria
4/23/2014

G Data
Win32.Application.Morstar
14.4.24

IKARUS anti.virus
not-a-virus:Downloader.Win32.Morstar
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.176.11861

Kaspersky
not-a-virus:Downloader.Win32.Morstar
14.0.0.3970

Malwarebytes
PUP.Optional.Rapiddown
v2014.04.23.11

NANO AntiVirus
Trojan.Win32.Morstar.creklv
0.28.0.59492

Reason Heuristics
PUP.Installer.SETUPPROCESS.T
14.8.8.3

Sophos
Solimba Installer
4.98

Vba32 AntiVirus
Downloader.Morstar
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
28554

File size:
244.4 KB (250,224 bytes)

Product version:
3.0.28.1

Copyright:
Copyright-©-2014

Original file name:
**intaller.exe**

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\pcmark%207%201.40.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
11/26/2013 4:00:00 PM

Valid to:
12/1/2014 4:00:00 AM

Subject:
CN=SETUPPROCESS, O=SETUPPROCESS, L=Badalona, S=Barcelona, C=ES

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0A8ABFC7C80D0C2F0A3A89CF6139A91D

File PE Metadata
Compilation timestamp:
1/22/2014 7:04:11 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:9UevXwS6tjih6eiXW6w/k1fKDjXiV7JXHZ1OP14X:eawS0ji3ixXfKK7BHu4X

Entry address:
0x711A0

Entry point:
60, BE, 00, F0, 43, 00, 8D, BE, 00, 20, FC, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.6966

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
204 KB (208,896 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to cdn.solimba.com  (95.211.6.35:80)

TCP (HTTP):
Connects to api.downloadmr.com  (95.211.39.161:80)

 
http://api.downloadmr.com/installer/12848076/launch

Remove pcmark 7 1.40.exe - Powered by Reason Core Security