virtualdub.exe

virtualdub

Solimba Aplicaciones S.L.

This is the Solimba installer program that will bundle additional offers mostly including adware and various unwanted PC utilities. The application virtualdub.exe by Solimba Aplicaciones S.L has been detected as adware by 30 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. The file has been seen being downloaded from d1w467en2eqqh2.cloudfront.net.
Publisher:
Solimba Aplicaciones S.L.  (signed and verified)

Product:
virtualdub

Version:
2.2.45.0

MD5:
fc05971ffa8daa1a16bba6618d30e2cd

SHA-1:
b92706a02bcab0b80c6239a99ee16533037b10c7

SHA-256:
a8c0b905482513456252c1047b37a6e838c8d68d92e995b34823aa10ca76ba31

Scanner detections:
30 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 10:10:06 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Solimba.1
899

Agnitum Outpost
Trojan.Adware
7.1.1

Avira AntiVirus
APPL/Solimba.Gen
7.11.168.26

avast!
Solimba-D [PUP]
140813-1

AVG
Adware AdInstaller.Q
2014.0.3986

Bitdefender
Gen:Variant.Adware.Solimba.1
1.0.20.1155

Clam AntiVirus
WIN.Adware.Solimba-3
0.98/19293

Comodo Security
Application.Win32.Solimba.K
19250

Dr.Web
Adware.Downware.798
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Solimba
8.14.08.19.09

ESET NOD32
MSIL/Solimba.H potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Solimba
8/19/2014

F-Prot
W32/Solimba.B.gen
4.6.5.141

F-Secure
Gen:Variant.Adware.Solimba.1
11.2014-19-08_3

G Data
Gen:Variant.Adware.Solimba
14.8.24

IKARUS anti.virus
PUA.Solimba
t3scan.1.7.5.0

K7 AntiVirus
Unwanted-Program
13.183.13098

Kaspersky
not-a-virus:AdWare.MSIL.Solimba
14.0.0.3380

Malwarebytes
PUP.BundleInstaller.SOL
v2014.08.19.09

MicroWorld eScan
Gen:Variant.Adware.Solimba.1
15.0.0.693

NANO AntiVirus
Riskware.Win32.Solimba.cudvtq
0.28.2.61721

Norman
Solimba.DIMI
11.20140819

Panda Antivirus
Adware/Solimba
14.08.19.09

Quick Heal
AdWare.MSIL.r3 (Not a Virus)
8.14.14.00

Reason Heuristics
PUP.SolimbaAplicacionesSL.K
14.8.19.18

Rising Antivirus
PE:Trojan.Win32.Generic.13F41FF6!334766070
23.00.65.14817

Sophos
Solimba Installer
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Solimba
10411

Vba32 AntiVirus
Signed-AdWare.MSIL.SolimbaAplicacionesSL
3.12.26.3

VIPRE Antivirus
Threat.4782980
32210

File size:
177.9 KB (182,136 bytes)

Copyright:
(c) 2010 (Build:2012-11-13 19:25)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\virtualdub.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/16/2011 2:00:00 AM

Valid to:
5/16/2013 1:59:59 AM

Subject:
CN=Solimba Aplicaciones S.L., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Solimba Aplicaciones S.L., L=Badalona, S=Barcelona, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
450EE582E26020D5F7632F2BECC6C5BD

File PE Metadata
Compilation timestamp:
8/30/2011 5:46:24 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.21

CTPH (ssdeep):
3072:HnOn7t7XpdpCCTg/sxFgJDC11cCvn7lxbnADucrbeIR3TTpNTqyOMimMnfOvRNL:HKpdcCrTqC31P7lxbnA397qZMiNOvb

Entry address:
0x4327

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 83, 42, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 84, 42, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 84, 42, 00, 56, A3, 40, 6B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 6B, 42, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, 84, 42, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Code size:
34.5 KB (35,328 bytes)

The file virtualdub.exe has been seen being distributed by the following URL.

Remove virtualdub.exe - Powered by Reason Core Security