itunes.exe

SOFTPULSE S.L.

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application itunes.exe by SOFTPULSE S.L has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. With this installer, users are expecting to download Apple's iTunes but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
SOFTPULSE S.L.  (signed and verified)

MD5:
48564750323a75b6118a15069f82adc6

SHA-1:
2d0ef3ebf8f0158932a0df92c03934c6e42b7d21

SHA-256:
0e436762af484d0ef4f7ffbb1e0847851d49a431e063bc13b7fb23a4141c1ff7

Scanner detections:
21 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 9:27:14 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.SoftPulse.AD
676

Agnitum Outpost
PUA.Downloader
7.1.1

AhnLab V3 Security
PUP/Win32.SoftPulse
2015.03.31

Avira AntiVirus
PUA/Softpulse.Gen
3.6.1.96

avast!
Win32:SoftPulse-ER [PUP]
2014.9-150401

AVG
SoftPulse
2016.0.3154

Bitdefender
Application.Bundler.SoftPulse.AD
1.0.20.450

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.Domaiq.185
9.0.1.090

Emsisoft Anti-Malware
Application.Bundler.SoftPulse.AD
8.15.03.31.07

Fortinet FortiGate
PossibleThreat
3/31/2015

F-Secure
Riskware.Application.Bundler.SoftPulse
11.2015-31-03_3

G Data
Application.Bundler.SoftPulse.AD
15.3.25

herdProtect (fuzzy)
2015.7.5.4

Kaspersky
not-a-virus:Downloader.Win32.DriverUpd
14.0.0.2263

MicroWorld eScan
Application.Bundler.SoftPulse.AD
16.0.0.270

Panda Antivirus
Trj/Genetic.gen
15.03.31.07

Reason Heuristics
PUP.Bundler.Softpulse
15.3.31.7

Sophos
PUA 'SoftPulse' (of type Adware)
5.12

VIPRE Antivirus
Threat.5064683
38882

Zillya! Antivirus
Downloader.DriverUpd.Win32.212
2.0.0.2126

File size:
562 KB (575,440 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\itunes.exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
7/8/2014 3:13:26 PM

Valid to:
7/8/2015 3:13:26 PM

Subject:
CN=SOFTPULSE S.L., O=SOFTPULSE S.L., L=Guia de Isora, C=ES

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B582684D0A7AC

File PE Metadata
Compilation timestamp:
3/30/2015 9:35:09 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:V8ELs/lt82qI1u9Ol/fSXNioWIS9DIkOU+/RqwrJSG4jh:V8KsbXqI1u9OxINoIS9EkmqwrJSljh

Entry address:
0x1000

Entry point:
B8, 94, 3D, 5E, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 4E, 2F, 50, DC, 53, 2D, 32, 82, DB, 91, DA, D5, FE, 63, 52, 77, A8, 11, 11, 5B, CA, 09, 54, EC, 40, 54, E8, 6C, 9D, 0C, B4, 50, D8, C1, 40, 22, 08, BF, 39, 8A, 3E, 07, 7A, 92, A7, 86, 6C, A4, D9, FC, 6E, 7A, 31, 1B, CB, C8, 03, 8B, 49, A3, 43, 59, 24, 73, 93, 39, D9, CD, E2, 7B, 49, E2, ED, 76, F5, DE, B1, EB, CF, A7, 2F, 70, 0E, DD, BC, 8D, 6B, E9, 95, 9D, 9E, 86, 5A...
 
[+]

Entropy:
7.9458

Packer / compiler:
PECompact v2

Code size:
1.2 MB (1,268,224 bytes)

The file itunes.exe has been seen being distributed by the following URL.

Remove itunes.exe - Powered by Reason Core Security