FIRSERIA, S.L.

Publisher Information

FIRSERIA, S.L. is a software publisher located in Badalona, Barcelona in Spain*. The company is a primary distributor of adware type software. Firseria (Solimba Aplicaciones S.L.) based on Spain is a company that runs various download portals including winportal.com and descargargratis.com which are designed as download sites that distribute legitimate 'Free Downloads', however they use a custom download manager (DownloadMR) to package bundled offers with each installation "Additionally, the download manager offers the optional installation of a toolbar.". These offeres include adware, toolbars and various other potential unwanted software. There is one additional code signing certificate issued to this publisher.
Authority:
Thawte, Inc.

Valid from:
7/24/2013 2:00:00 AM

Valid to:
7/25/2014 1:59:59 AM

Subject:
CN="FIRSERIA, S.L.", OU=IT, O="FIRSERIA, S.L.", L=Badalona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
73c4780fac0cd497b0778732fb8af673

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Avira AntiVirus
APPL/Firseria.A.13, TR/Crypt.XPACK.Gen, TR/Dropper.Gen, APPL/Firseria.Gen, TR/Crypt.ULPM.Gen, APPL/Firseria.A.3, APPL/Firseria.B
100.00%

Reason Heuristics
PUP.Installer.FIRSERIASL.P, PUP.FIRSERIASL.M, PUP.Installer.FIRSERIASL.K, PUP.Installer.FIRSERIASL.CC, PUP.Installer.FIRSERIASL.H, PUP.FIRSERIASL.S, PUP.Installer.FIRSERIASL.V, PUP.FIRSERIASL.BB, PUP.FIRSERIASL.G, PUP.Installer.FIRSERIASL.g, PUP.FIRSERIASL.V, PUP.FIRSERIASL.Q, PUP.FIRSERIASL.T, PUP.Installer.FIRSERIASL.I, PUP.FIRSERIASL.U, PUP.FIRSERIASL.J, PUP.FIRSERIASL.N, PUP.FIRSERIASL.K, PUP.Installer.FIRSERIASL.J, PUP.Installer.FIRSERIASL.W, PUP.FIRSERIASL.I, PUP.FIRSERIASL.DD, PUP.FIRSERIASL.X, PUP.FIRSERIASL.F, PUP.FIRSERIASL.Y, PUP.Installer.FIRSERIASL.S, PUP.FIRSERIASL.W, PUP.Installer.FIRSERIASL.F
100.00%

AVG
Adware AdInstaller.Firseria, BundleApp
100.00%

VIPRE Antivirus
Threat.4782980, Threat.4150696, Threat.4895151, DownloadMR, Trojan.Win32.Generic
100.00%

avast!
Win32:Firseria-A [PUP], Win32:PUP-gen [PUP]
100.00%

Dr.Web
Adware.Downware.1433, Adware.Downware.1433, Adware.Downware.1433, Adware.Downware.1424, Trojan.DownLoader10.51613, Trojan.DownLoader10.9253
98.00%

Kaspersky
not-a-virus:Downloader.Win32.Firser, not-a-virus:Downloader.Win32.Morstar, not-a-virus:AdWare.Win32.Fiseria
98.00%

Comodo Security
TrojWare.Win32.Trojan.Obfuscated.~EN, Application.Win32.Solimba.J
96.00%

G Data
Gen:Application.Bundler.Firseria, Win32.Application.FirseriaInstaller, Gen:Variant.Applicaton.Jaik.2123
96.00%

Vba32 AntiVirus
Downware.Morstar, Signed-Downware.Morstar.FIRSERIA, Downloader.Firser, Downloader.Morstar
96.00%

7 / 68      (Adware)
setup.exe (by Firseria)  (96f768be3ee8df38af75e83ac190c5ef)

34 / 68    (Adware)
songr.exe (by Firseria·s·l·)  (93afc798f57f5a7796c93dae2dd65c1d)

31 / 68    (Adware)
advanced uninstaller.exe (by ·Firseria·sl·)  (45aba660565147ec3197380c5f6cf7fb)

32 / 68    (Adware)
windows live movie maker.exe (by Firseria·s·l·)  (2178fc6e6897945d3848ecd42113ae73)

35 / 68    (Adware)
photoscape.exe (by Appinstallr)  (de67fcc64871d0886395f17b96ec8059)

31 / 68    (Adware)
windows defender.exe (by Firseria)  (910949be6a089591da6d5e90810abfe2)

36 / 68    (Adware)
avs_media_player.exe (by Firseria·s·l·)  (90463d49b57250387c082c41449ff005)

37 / 68    (Adware)
star wars- empire at war.exe (by Firseria·s·l·)  (9c467326a902172fb6ead42541829a3a)

35 / 68    (Adware)
flv_media_player.exe (by Firseria·s·l·)  (93277869aa1b2a6f5a60a7620fedd60f)

36 / 68    (Adware)
family keylogger.exe (by Firseria·s·l·)  (cb70efe845d8fb6fd5db4978c4a4f109)

32 / 68    (Adware)
adobe acrobat 9 pro extended.exe (by Firser)  (e7f5b7319e41069f7cdf26ab805d126e)

36 / 68    (Adware)
7-zip.exe (by F¡rser¡a s·l·)  (382bc0b0061684ad36546ebc753fabb9)

18 / 68    (Adware)
adwcleaner.exe (by Rapiddown)  (fb7f678de70fcc085f3826318c1f9994)

32 / 68    (Adware)

32 / 68    (Adware)
java j2sdk.exe (by Firser)  (d3a1f10d5a6776fac3740209cd12fbdb)

33 / 68    (Adware)
java 8 jdk 32bits.exe (by Firser)  (35b4bbbae4cd4a7998b765c086d44d80)

36 / 68    (Adware)
flv_media_player.exe (by F¡rser¡a s·l·)  (c41041b6e857d3fcb4658e2584d8b2f6)

21 / 68    (Adware)
avs_media_player.exe (by F¡rser¡a s·l·)  (cf398f7c474520822401f7e905f72b9d)

30 / 68    (Adware)
google chrome.exe (by Firseria)  (77acdc456687a692d6fc6e00b50bda87)

31 / 68    (Adware)
imgburn.exe (by Firseria)  (cd72c5b8f0c3284d420aef18a326e7ef)

9 / 68      (Adware)
windows media player 11.exe (by Firseria s·l·)  (dd1644f8f011c842b4cf982354ad3d39)

36 / 68    (Adware)
winrar.exe (by Firseria·s·l·)  (8b47987e162955594b6515bc9432183b)

36 / 68    (Adware)
flv_media_player.exe (by Firseria·s·l·)  (f117027b34c4d94a311ee66bdf61ff9d)

38 / 68    (Adware)
skype.exe (by Firseria·s·l·)  (f66b45e4b7a31c19f8a1bb49096416c3)

35 / 68    (Adware)
freecall.exe (by Firseria·s·l·)  (09dfc536beade0b50b2c18e7f08df710)

33 / 68    (Adware)
windows live messenger.exe (by Firser)  (f98fc0e7519b8ed8ad6b6e7e28695e4a)

31 / 68    (Adware)
avast! free antivirus.exe (by Firseria)  (9c3329f4fed5cdde1ca3143c9b5be846)

31 / 68    (Adware)
itunes.exe (by Firseria)  (3361d7f7b309f80a76aa5f16f4dc426e)

36 / 68    (Adware)
dvr studio.exe (by Firseria·s·l·)  (c67b692e2adfa5b0a39c30c4e754ee77)

33 / 68    (Adware)
microsoft office 2010.exe (by Firseria)  (130db809dc2544a08502e00ae7fd92f2)

 
Latest 30 of 827 files

Downloads URLs for files signed by FIRSERIA, S.L..

36 / 68    (Adware)
http://dl01.fabdmr.com/n/.../AVS_Media_Player.exe  (90463d49b57250387c082c41449ff005)

36 / 68    (Adware)
http://dl.d0wnpzivrubajjui.com/n/3.0.21/.../Winrar.exe  (8b47987e162955594b6515bc9432183b)

36 / 68    (Adware)
http://dl.secdown.com/n/.../FLV_Media_Player.exe  (f117027b34c4d94a311ee66bdf61ff9d)

31 / 68    (Adware)

35 / 68    (Adware)

29 / 68    (Adware)

25 / 68    (Adware)

Top-level domains owned by FIRSERIA, S.L..

The following websites host and distribute files published by FIRSERIA, S.L..

The following certificate is also signed by FIRSERIA, S.L..

7658ACC15B33D93ABD5A967181DEF901  (Jul 24, 2014 to Jul 23, 2016)

The following publishers (by Authenticode signature organization name) are related.

Detection Incidence by Country
* Note, the details and description above are based on the code signing digital signature issued to FIRSERIA, S.L. by Thawte, Inc. on July 24, 2013 with the serial number '73c4780fac0cd497b0778732fb8af673'.