spybot search & destroy.exe

Spybot Search & Destroy

Bechiro S.L.

This is the Solimba installer program that will bundle additional offers mostly including adware and various unwanted PC utilities. The application spybot search & destroy.exe, “Spybot Search & Destroy AppInstaller” by Bechiro S.L has been detected as adware by 18 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. With this installer, users are expecting to download Spybot - Search & Destroy but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Bechiro S.L.  (signed and verified)

Product:
Spybot Search & Destroy

Description:
Spybot Search & Destroy AppInstaller

Version:
3.0.17.6

MD5:
337cb22cc10c97afa60744b989c6ab21

SHA-1:
343b99379a5da0e61894fcef4c836e0029034e74

SHA-256:
6e625f4b573f67334d902b14ef3d678ee31a77826b556b8539b64db8222c4ddd

Scanner detections:
18 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/17/2024 11:57:58 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Solimba
7.1.1

Avira AntiVirus
APPL/Solimba.Gen
7.11.206.0

AVG
Adware Skodna.Generic.AMG
2014.0.4253

Comodo Security
Application.Win32.Solimba.L
20902

Dr.Web
Adware.Downware.1302
9.0.1.05190

ESET NOD32
MSIL/Solimba potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Solimba
1/30/2015

G Data
MSIL.Application.Solimba
15.1.25

K7 AntiVirus
Unwanted-Program
13.193.14817

Kaspersky
not-a-virus:Downloader.Win32.Solimba
15.0.0.543

Malwarebytes
PUP.Optional.Solimba
v2015.01.30.03

NANO AntiVirus
Trojan.Win32.DownLoad3.daevxj
0.30.0.65070

Panda Antivirus
Adware/Firseria
15.01.30.03

Reason Heuristics
PUP.Installer.Solimba
15.1.30.14

Sophos
PUA 'Solimba Installer'
5.10

SUPERAntiSpyware
Adware.Solimba/Variant
10084

Vba32 AntiVirus
Signed-Downware.Morstar.BechiroSL
3.12.26.3

VIPRE Antivirus
Threat.4782980
36694

File size:
281.9 KB (288,664 bytes)

Copyright:
AppInstaller 2013 (132191027)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\spybot search & destroy.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/12/2012 8:00:00 PM

Valid to:
6/13/2014 7:59:59 PM

Subject:
CN=Bechiro S.L., OU=Devel, O=Bechiro S.L., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
738DCAC697C06E1B89D106073773010D

File PE Metadata
Compilation timestamp:
2/19/2012 10:01:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
6144:hsaocyLCw+4SnoU7rY3RzIxKFXTbhMubCwnOYgAm+XLD:htobr8chzdFjbfbNOSTf

Entry address:
0x4327

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 93, 42, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 94, 42, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 94, 42, 00, 56, A3, 40, 7B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 7B, 42, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, 94, 42, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Code size:
34.5 KB (35,328 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to cdn.solimba.com  (95.211.6.35:80)

TCP (HTTP):
Connects to api.downloadmr.com  (95.211.39.161:80)

 
http://api.downloadmr.com/installer/51061680/launch

Remove spybot search & destroy.exe - Powered by Reason Core Security