google-chrome.exe

Smart Secure Software S.l.

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application google-chrome.exe by Smart Secure Software S.l has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The installer is marketed through download protals and search ads as Google's Chrome web browser but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Smart Secure Software S.l.  (signed and verified)

MD5:
5259fb14f758a099ba2499589522a1ce

SHA-1:
b0369f3d041b11764524ac45f0f40df9e76b632c

Scanner detections:
12 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/1/2024 7:43:57 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.DomaIQ.14
484

avast!
Win32:SoftPulse-H [PUP]
2014.9-151008

Bitdefender
Gen:Variant.Application.Bundler.DomaIQ.14
1.0.20.1405

ESET NOD32
Win32/SoftPulse.F potentially unwanted application
9.7.0.302.0

herdProtect (fuzzy)
2015.10.8.19

K7 AntiVirus
Unwanted-Program
13.180.12612

McAfee
CryptDomaIQ
5600.6618

MicroWorld eScan
Gen:Variant.Application.Bundler.DomaIQ.14
16.0.0.843

Reason Heuristics
PUP.Softpulse.SmartSecureSoftwareSl.Bundler (M)
15.8.20.19

Sophos
SoftPulse
4.98

VIPRE Antivirus
Threat.4783262
29708

Zillya! Antivirus
Downloader.Agent.Win32.198116
2.0.0.1845

File size:
1.2 MB (1,260,960 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\Documents and Settings\{user}\My documents\downloads\google-chrome.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/17/2014 5:59:49 AM

Valid to:
6/18/2015 5:59:49 AM

Subject:
E=contact@smartsecuresoftware.com, CN=Smart Secure Software S.l., O=Smart Secure Software S.l., S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E50EC4A4247FFA7B123476B988982563

File PE Metadata
Compilation timestamp:
7/1/2014 10:34:09 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:hWLjWdykSBLgdNxJMfonoUT6pXGZWRW7MG/RMZZe22Ue21:hgzWdNonUT4+MR

Entry address:
0x80AC

Entry point:
E8, 66, 61, 00, 00, E9, 39, FE, FF, FF, E9, ED, 49, 00, 00, FF, 35, 80, A0, 43, 00, FF, 15, 24, 61, 42, 00, C3, FF, 35, 80, A0, 43, 00, FF, 15, 24, 61, 42, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, C3, 58, 00, 00, 6A, 01, 6A, 00, E8, 4F, 68, 00, 00, 83, C4, 0C, E9, 66, 68, 00, 00, 55, 8B, EC, 56, FF, 35, 80, A0, 43, 00, FF, 15, 24, 61, 42, 00, FF, 75, 08, 8B, F0, FF, 15, 20, 61, 42, 00, A3, 80, A0, 43, 00, 8B, C6, 5E, 5D, C3, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, A3, 6A, 00, 00, 59, 85, C0, 74, 0F...
 
[+]

Entropy:
7.5912

Code size:
148 KB (151,552 bytes)

The file google-chrome.exe has been seen being distributed by the following URL.

Remove google-chrome.exe - Powered by Reason Core Security