winqsb.exe

WinQSB

Apps Installer S.L.

This is the Solimba installer program that will bundle additional offers mostly including adware and various unwanted PC utilities. The application winqsb.exe by Apps Installer S.L has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. While running, it connects to the Internet address cdn.solimba.com on port 80 using the HTTP protocol.
Publisher:
Apps Installer S.L.  (signed and verified)

Product:
WinQSB

Description:
WinQSB installer

Version:
3.0.4.2

MD5:
69d03ad2c558963d2df821334f43b841

SHA-1:
d2fd00246c5fc2b3edef43ae3887d72a0c9a1379

SHA-256:
5e91db8a7894d6887c2aba2dbbd80f3c6fcb85de9d014803df0e42e44e5607fe

Scanner detections:
12 / 68

Status:
Adware

Explanation:
This is a wrapped installation of legitimate software (without persmission of the developer) and bundles adware such as toolbars and extensions.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 5:21:00 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Solimba.Gen
7.11.179.162

avast!
Solimba-C [PUP]
141003-0

Dr.Web
Adware.Downware.1125
9.0.1.05190

ESET NOD32
MSIL/Solimba.L potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Solimba
10/19/2014

K7 AntiVirus
Unwanted-Program
13.184.13727

Kaspersky
not-a-virus:AdWare.Win32.Fiseria
15.0.0.494

NANO AntiVirus
Riskware.Win32.Vpatch.dapviz
0.28.2.62671

Reason Heuristics
PUP.Installer.AppsInstallerSL.G
14.10.19.22

Sophos
DownloadMR
4.98

Vba32 AntiVirus
Signed-Downware.Morstar.AppsInstallerSL
3.12.26.3

VIPRE Antivirus
Threat.4782980
33706

File size:
296.2 KB (303,272 bytes)

Copyright:
(c) 2010-2013 (201305071447)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\users\{user}\downloads\winqsb.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
2/18/2013 7:00:00 PM

Valid to:
2/19/2015 6:59:59 PM

Subject:
CN=Apps Installer S.L., O=Apps Installer S.L., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
323F44D66AEF890F43C32CFD743A4AD0

File PE Metadata
Compilation timestamp:
2/19/2012 10:01:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
6144:XsaocyLCy1d9+FdlHKZenYxwdJ/jRziKRPar1lx61vAq:Xtobxd9+f03xKJ/jZiMwFoH

Entry address:
0x4327

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 93, 42, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 94, 42, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 94, 42, 00, 56, A3, 40, 7B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 7B, 42, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, 94, 42, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Code size:
34.5 KB (35,328 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to cdn.solimba.com  (95.211.6.35:80)

TCP (HTTP):
Connects to api.downloadmr.com  (95.211.39.161:80)

 
http://api.downloadmr.com/installer/36535620/launch

Remove winqsb.exe - Powered by Reason Core Security