recuva.exe

XLIV-II desidero mando

FIRSERIA, S.L.

The setup program uses the Firseria/Solimba AppInstaller (DownloadMR) which is a monetization download manager that bundles additional adware offers, typically by wrapping legitimate applications. The application recuva.exe, “terror tendo proventus” by FIRSERIA, S.L has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
proficio sive  (signed by FIRSERIA, S.L.)

Product:
XLIV-II desidero mando

Description:
terror tendo proventus

Version:
7.38.11.67

MD5:
ed3d940c8b13045b63747499b794ca9e

SHA-1:
c6f0e9bdbfe576acd111e016b4597d27993e1e29

SHA-256:
d8fd54bdce494cc01c9cf61b3267bc9b9aa7512bc012846a70d71b3974f938ab

Scanner detections:
19 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 5:48:34 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Firseria.M
836

Avira AntiVirus
APPL/Solimba.Gen4
7.11.180.106

AVG
Adware BundleApp_r.AV
2014.0.4040

Bitdefender
Application.Bundler.Firseria.M
1.0.20.1475

Comodo Security
Application.Win32.Solimba.LSW
19870

Dr.Web
Adware.Downware.8808
9.0.1.05190

Emsisoft Anti-Malware
Application.Bundler.Firseria.M
14.10.22

ESET NOD32
MSIL/Solimba.AH potentially unwanted application
7.0.302.0

F-Prot
W32/A-a1e0d357
v6.4.7.1.166

F-Secure
Application.Bundler.Firseria
11.2014-22-10_4

G Data
Application.Bundler.Firseria
14.10.24

IKARUS anti.virus
AdWare.BundleApp
t3scan.1.7.8.0

Kaspersky
not-a-virus:Downloader.Win32.Morstar
15.0.0.494

Malwarebytes
PUP.Optional.Solimba
v2014.10.22.02

MicroWorld eScan
Application.Bundler.Firseria.M
15.0.0.885

Reason Heuristics
PUP.FIRSERIASL.G
14.10.22.1

Sophos
Solimba Installer
4.98

Vba32 AntiVirus
Downware.Morstar
3.12.26.3

VIPRE Antivirus
Threat.4782980
33706

File size:
538.2 KB (551,104 bytes)

Product version:
58.53.88.80

Copyright:
2014 exitium improbus

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\users\{user}\downloads\recuva.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/24/2014 9:00:00 PM

Valid to:
7/23/2016 8:59:59 PM

Subject:
CN="FIRSERIA, S.L.", O="FIRSERIA, S.L.", L=Badalona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7658ACC15B33D93ABD5A967181DEF901

File PE Metadata
Compilation timestamp:
10/21/2014 7:59:41 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:YmwDie98eTIQW6vkqw+ecC8rIXtM9likmmW0rf7QDZVF:YmwDSeTH7w+ecpId5AEFVF

Entry address:
0xDEFC

Entry point:
E8, AE, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 18, 70, 42, 00, E8, FE, 15, 00, 00, E8, 7F, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 41, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 0A, 65, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
113.5 KB (116,224 bytes)

Remove recuva.exe - Powered by Reason Core Security