windows defender.exe

POPELER SYSTEM, S.L.

The setup program uses the Firseria/Solimba AppInstaller (DownloadMR) which is a monetization download manager that bundles additional adware offers, typically by wrapping legitimate applications. The application windows defender.exe by POPELER SYSTEM, S.L has been detected as adware by 31 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Installation helper  (signed by POPELER SYSTEM, S.L.)

Product:
Installation helper

Version:
3.1.13.33

MD5:
f220f5e4698f4fa443cd1f9953dc425f

SHA-1:
3f777116929c0269e5ceddf6a985fcf4096badbc

SHA-256:
e0a5a58d2aee52dac6e19821c530e79fe3513d80de74bc9b79e796d59f49ad6d

Scanner detections:
31 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 11:19:27 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Firseria.7
5582423

Agnitum Outpost
PUA.Fiseria
7.1.1

AhnLab V3 Security
PUP/Win32.Firseria
2015.05.30

Avira AntiVirus
PUA/Firseria.Gen8
8.3.1.6

avast!
Win32:Solimba-S [PUP]
150525-2

AVG
Adware BundleApp.FW
2014.0.4311

Bitdefender
Gen:Variant.Application.Bundler.Firseria.7
1.0.20.750

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.FirseriaInstaller.HYM
22274

Dr.Web
Trojan.MulDrop5.34145
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.Firseria
10.0.0.5366

ESET NOD32
Win32/FirseriaInstaller.M potentially unwanted application
7.0.302.0

Fortinet FortiGate
W32/Generic.AC.88097
5/30/2015

F-Prot
W32/A-1d7b3bb9
v6.4.7.1.166

F-Secure
Riskware.Gen:Variant.Application.Bundler
5.14.151

G Data
Gen:Variant.Application.Bundler.Firseria
15.5.25

IKARUS anti.virus
PUA.FirseriaInstaller
t3scan.1.9.2.0

K7 AntiVirus
Trojan
13.204.16076

Kaspersky
not-a-virus:Downloader.Win32.Morstar
15.0.0.543

Malwarebytes
PUP.Optional.FirseriaInstaller
v2015.05.30.01

MicroWorld eScan
Gen:Variant.Application.Bundler.Firseria.7
16.0.0.450

NANO AntiVirus
Riskware.Win32.Kazy.dgpkyj
0.30.24.1636

Norman
Gen:Variant.Application.Bundler.Firseria.7
03.12.2014 13:20:04

Panda Antivirus
Adware/Firseria
15.05.30.01

Quick Heal
Adware.Firseria.A3
5.15.14.00

Reason Heuristics
PUP.Solimba.POPELERSYSTEM
15.5.30.1

Rising Antivirus
PE:Malware.FirseriaInstaller!6.19E3
23.00.65.15528

Sophos
PUA 'Solimba Installer'
5.14

Vba32 AntiVirus
Downware.Morstar
3.12.26.4

VIPRE Antivirus
Threat.4782980
40552

Zillya! Antivirus
Adware.Agent.Win32.10272
2.0.0.2196

File size:
404.3 KB (414,016 bytes)

Product version:
3.1.19

Copyright:
© 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\windows defender.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
8/29/2013 10:00:00 AM

Valid to:
8/30/2014 9:59:59 AM

Subject:
CN="POPELER SYSTEM, S.L.", OU=IT, O="POPELER SYSTEM, S.L.", L=Badalona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
58806C1A153885D4BFE2E3370340491F

File PE Metadata
Compilation timestamp:
7/11/2014 7:35:45 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:dgffF5hZ2v2hiPO8WI4iU83wGqMgvOc5X/d:dgXRzb8WIK838735Xl

Entry address:
0x820A4

Entry point:
60, E8, 00, 00, 00, 00, 58, 05, 5A, 0B, 00, 00, 8B, 30, 03, F0, 2B, C0, 8B, FE, 66, AD, C1, E0, 0C, 8B, C8, 50, AD, 2B, C8, 03, F1, 8B, C8, 57, 51, 49, 8A, 44, 39, 06, 88, 04, 31, 75, F6, 2B, C0, AC, 8B, C8, 80, E1, F0, 24, 0F, C1, E1, 0C, 8A, E8, AC, 0B, C8, 51, 02, CD, BD, 00, FD, FF, FF, D3, E5, 59, 58, 8B, DC, 8D, A4, 6C, 90, F1, FF, FF, 51, 2B, C9, 51, 51, 8B, CC, 51, 66, 8B, 17, C1, E2, 0C, 52, 57, 83, C1, 04, 51, 50, 83, C1, 04, 56, 51, E8, 5E, 00, 00, 00, 8B, E3, 5E, 5A, 2B, C0, 89, 04, 32, B4, 10...
 
[+]

Entropy:
7.9759

Packer / compiler:
ASPack v1.08.04

Code size:
121 KB (123,904 bytes)

The file windows defender.exe has been seen being distributed by the following URL.

Remove windows defender.exe - Powered by Reason Core Security