google chrome.exe

Softpulse S.l.

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application google chrome.exe by Softpulse S.l has been detected as adware by 23 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. With this installer, users are expecting to download Google's Chrome web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Softpulse S.l.  (signed and verified)

MD5:
3d4c39e7ebd7cf560cf31cd588c6bebf

SHA-1:
67d013ac263e586d368f90f2527e5f83daa5e5ab

SHA-256:
107ba6f9ff2bcf93f66ae6a19b2736af5c9534fcac94879cb2533c4d7d078ebb

Scanner detections:
23 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/2/2024 4:16:22 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.SoftPulse.AD
673

Agnitum Outpost
PUA.Downloader
7.1.1

AhnLab V3 Security
PUP/Win32.SoftPulse
2015.04.04

Avira AntiVirus
W32/Ramnit.C
7.11.30.172

avast!
Win32:SoftPulse-ER [PUP]
2014.9-150403

AVG
Generic
2016.0.3151

Bitdefender
Application.Bundler.SoftPulse.AD
1.0.20.465

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.Domaiq.185
9.0.1.093

Emsisoft Anti-Malware
Application.Bundler.SoftPulse.AD
8.15.04.03.10

ESET NOD32
Win32/SoftPulse.Z potentially unwanted (variant)
9.11421

Fortinet FortiGate
PossibleThreat
4/3/2015

F-Secure
Riskware.Application.Bundler.SoftPulse
11.2015-03-04_6

G Data
Application.Bundler.SoftPulse.AD
15.4.25

herdProtect (fuzzy)
2015.7.8.1

Kaspersky
not-a-virus:Downloader.Win32.DriverUpd
14.0.0.2248

MicroWorld eScan
Application.Bundler.SoftPulse.AD
16.0.0.279

NANO AntiVirus
Trojan.Win32.DriverUpd.dpyela
0.30.8.659

Panda Antivirus
Trj/Genetic.gen
15.04.03.10

Reason Heuristics
Threat.Softpulse.Bundler
15.4.3.10

Sophos
PUA 'SoftPulse' (of type Adware)
5.12

VIPRE Antivirus
Threat.5064683
38882

Zillya! Antivirus
Downloader.DriverUpd.Win32.212
2.0.0.2126

File size:
562.3 KB (575,816 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\google chrome.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/23/2014 1:00:00 AM

Valid to:
7/24/2015 12:59:59 AM

Subject:
CN=Softpulse S.l., O=Softpulse S.l., L=Guia de Isora, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
492522DB26914D38C21A797768B88A13

File PE Metadata
Compilation timestamp:
3/30/2015 9:35:09 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:R8ELs/lt82qI1u9Ol/fSXNioWIS9DIkOU+/RqwrJSG4j+:R8KsbXqI1u9OxINoIS9EkmqwrJSlj+

Entry address:
0x1000

Entry point:
B8, 94, 3D, 5E, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 4E, 2F, 50, DC, 53, 2D, 32, 82, DB, 91, DA, D5, FE, 63, 52, 77, A8, 11, 11, 5B, CA, 09, 54, EC, 40, 54, E8, 6C, 9D, 0C, B4, 50, D8, C1, 40, 22, 08, BF, 39, 8A, 3E, 07, 7A, 92, A7, 86, 6C, A4, D9, FC, 6E, 7A, 31, 1B, CB, C8, 03, 8B, 49, A3, 43, 59, 24, 73, 93, 39, D9, CD, E2, 7B, 49, E2, ED, 76, F5, DE, B1, EB, CF, A7, 2F, 70, 0E, DD, BC, 8D, 6B, E9, 95, 9D, 9E, 86, 5A...
 
[+]

Entropy:
7.9458

Packer / compiler:
PECompact v2

Code size:
1.2 MB (1,268,224 bytes)

The file google chrome.exe has been seen being distributed by the following URL.

Remove google chrome.exe - Powered by Reason Core Security