utorrent.exe

PortalProgramas

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application utorrent.exe, “ Application Install ” by PortalProgramas has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. The file has been seen being downloaded from dl.downloadohdooshieyei.com.
Publisher:
Setup·process  (signed by PortalProgramas)

Description:
Application Install

Version:
3.0.30.11

MD5:
fb0bb7fc82ab2960553b433cdd3f333d

SHA-1:
8b2f671f377155d1b22e84f85c6d8d069c9b2d29

SHA-256:
9d78188eb8460ccf8a2da9bd8128af811f4be0f35fc7e375ed837f921f62cc09

Scanner detections:
20 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/26/2024 4:07:36 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Solimba
7.1.1

Avira AntiVirus
APPL/Firseria.5585
7.11.134.182

AVG
MalSign.Solimba
2015.0.3503

Dr.Web
Adware.Downware.2167
9.0.1.0106

ESET NOD32
Win32/FirseriaInstaller (variant)
8.9499

Fortinet FortiGate
Riskware/Morstar
4/16/2014

G Data
Win32.Application.Morstar
14.4.24

herdProtect (fuzzy)
2014.6.13.3

IKARUS anti.virus
not-a-virus:Downloader.Win32.Morstar
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.176.11784

Kaspersky
not-a-virus:Downloader.Win32.Morstar
14.0.0.4008

Malwarebytes
PUP.Optional.Solimba
v2014.04.16.11

NANO AntiVirus
Trojan.Win32.Morstar.cumkck
0.28.0.59288

Panda Antivirus
Trj/Genetic.gen
14.04.16.11

Reason Heuristics
PUP.Installer.PortalProgramas.I
14.8.8.0

Rising Antivirus
PE:Malware.Morstar!6.149A
23.00.65.14414

Sophos
Solimba Installer
4.98

SUPERAntiSpyware
Adware.Morstar/Variant
10662

Vba32 AntiVirus
Downware.Morstar
3.12.24.3

VIPRE Antivirus
DownloadMR
27072

File size:
288.4 KB (295,328 bytes)

Product version:
3.0.30

Copyright:
Copyright © 2013·14

Original file name:
setupinstaller.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/2/2014 7:30:00 PM

Valid to:
1/3/2015 7:29:59 PM

Subject:
CN=PortalProgramas, OU=Tech, O=PortalProgramas, STREET="Balmes 1, primera planta", L=Terrassa, S=Barcelona, PostalCode=08225, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FD1E07CCAABD98839CDBE058C9F8B3E9

File PE Metadata
Compilation timestamp:
2/25/2014 12:32:37 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:dmRZ2W5Ij46YOG0G+EQ2eiAIQibh8HOlxHUbx1LqrGo:d6H67bG0lEQ2kioOlNUv2rGo

Entry address:
0xD7B9

Entry point:
E8, C8, 79, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 60, 44, 42, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 64, 44, 42, 00, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, BA, 58, 00, 00, 85, C0, 75, 06, B8, C8, 45, 42, 00, C3, 83, C0, 08, C3, E8, A7, 58, 00, 00, 85, C0, 75, 06, B8, CC, 45, 42, 00, C3, 83, C0, 0C, C3, 8B, FF, 55, 8B, EC, 56, E8, E2, FF, FF, FF, 8B, 4D, 08...
 
[+]

Code size:
111.5 KB (114,176 bytes)

The file utorrent.exe has been seen being distributed by the following URL.

Remove utorrent.exe - Powered by Reason Core Security