windows_media_player.exe

FIRSERIA, S.L.

The setup program uses the Firseria/Solimba AppInstaller (DownloadMR) which is a monetization download manager that bundles additional adware offers, typically by wrapping legitimate applications. The application windows_media_player.exe, “Installer Application” by FIRSERIA, S.L has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Firseria  (signed by FIRSERIA, S.L.)

Description:
Installer Application

Version:
1, 0, 0, 1

MD5:
577b05f96ea2fe93b986023a53b0b715

SHA-1:
0e93e0d6f84d8edb7eb2c6d2f533c69b41e7cef7

SHA-256:
b069b5e18f4d901453334e26c4578bde8562c197fb43bd7f7f4b91d443befe76

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 8:29:54 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Solimba
7.1.1

Avira AntiVirus
TR/Dropper.Gen
7.11.144.158

avast!
Win32:PUP-gen [PUP]
2014.9-151031

Comodo Security
Application.Win32.Solimba.J
18141

Dr.Web
Trojan.DownLoader10.9253
9.0.1.0304

herdProtect (fuzzy)
2015.10.31.15

K7 AntiVirus
Unwanted-Program
13.176.11806

Malwarebytes
PUP.Optional.Solimba.mr
v2015.10.31.03

NANO AntiVirus
Trojan.Win32.DownLoader10.cwczsq
0.28.0.59288

Reason Heuristics
PUP.Solimba.FIRSERIA.Bundler (M)
15.9.4.21

SUPERAntiSpyware
Adware.Solimba
9536

VIPRE Antivirus
DownloadMR
28454

File size:
193.3 KB (197,944 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2013

Original file name:
installer.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\windows_media_player.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/23/2013 8:00:00 PM

Valid to:
7/24/2014 7:59:59 PM

Subject:
CN="FIRSERIA, S.L.", OU=IT, O="FIRSERIA, S.L.", L=Badalona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
73C4780FAC0CD497B0778732FB8AF673

File PE Metadata
Compilation timestamp:
8/22/2013 9:48:29 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:MjAvo7lBultySqPBP0TR2c3rWIG2gUwr0aQ88IphDF5LtDQ7nE/W4GfogdorIPE:MjJD6IaTR2c3UN0b88IphDNDbe40CIM

Entry address:
0x74D40

Entry point:
60, BE, 00, B0, 44, 00, 8D, BE, 00, 60, FB, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.7972

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
168 KB (172,032 bytes)

Remove windows_media_player.exe - Powered by Reason Core Security