microsoft-office-2010.exe

Sambamedia SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application microsoft-office-2010.exe by Sambamedia SL has been detected as adware by 27 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
Sambamedia SL  (signed and verified)

MD5:
fb820a978d5dd26dfbd5a07174cd4156

SHA-1:
889eef937bf64a586b51afa47254d520da79eba4

SHA-256:
6dc0440d0fb3858867998eea5c74fdaf1319cc418db72f0d25bb15be567c4a20

Scanner detections:
27 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 6:26:21 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Symmi.46906
842

AegisLab AV Signature
Troj.W32.Vilsel
2.1.4+

Agnitum Outpost
PUA.Downloader
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
2014.10.16

Avira AntiVirus
APPL/Softpulse.Gen8
7.11.178.140

avast!
Win32:SoftPulse-A [PUP]
141003-0

AVG
Generic
2015.0.3320

Bitdefender
Gen:Variant.Adware.Symmi.46906
1.0.20.1440

Clam AntiVirus
Win.Trojan.Inject-10285
0.98/21411

Dr.Web
Adware.Downware.5055
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.DomaIQ.14
14.10.15

ESET NOD32
Win32/SoftPulse.D potentially unwanted application
7.0.302.0

F-Prot
W32/A-59a867b1
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Symmi.46906
11.2014-15-10_4

G Data
Gen:Variant.Adware.Symmi.46906
14.10.24

IKARUS anti.virus
Trojan.Inject
t3scan.1.7.8.0

K7 AntiVirus
Unwanted-Program
13.183.13690

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3097

McAfee
CryptDomaIQ
5600.6976

MicroWorld eScan
Gen:Variant.Adware.Symmi.46906
15.0.0.864

NANO AntiVirus
Trojan.Win32.Inject.dbobdv
0.28.2.62671

Norman
Malware
11.20141015

Quick Heal
Trojan.Buzus.B4
10.14.14.00

Reason Heuristics
PUP.SambamediaSL.V
14.10.15.12

Sophos
SoftPulse
4.98

Vba32 AntiVirus
Trojan.Inject
3.12.26.3

Zillya! Antivirus
Trojan.Inject.Win32.75845
2.0.0.1956

File size:
1.2 MB (1,244,104 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\microsoft-office-2010.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
4/28/2014 8:13:17 AM

Valid to:
4/29/2015 8:13:17 AM

Subject:
E=contact@sambamediasl.com, CN=Sambamedia SL, O=Sambamedia SL, L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A6F5CA8560763435DF885221AE3B200F

File PE Metadata
Compilation timestamp:
6/13/2014 8:15:51 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:chRyk5BKO3gux5cGnWYu2qR3Jai7r9rfPn9vYjzNJJJJJJJJJJJJJ7JJJJJOnOny:ch4qvQImGWYu2w7NmnO

Entry address:
0x3B5D

Entry point:
E8, 7F, 38, 00, 00, E9, 39, FE, FF, FF, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 5F, 00, 00, 00, C7, 06, 5C, BA, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 5F, 00, 00, 00, C7, 06, 5C, BA, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, A0, 00, 00, 00, C7, 06, 44, BA, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 44, 00, 00, 00, C7, 06, 44, BA, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1...
 
[+]

Entropy:
7.5799

Code size:
100 KB (102,400 bytes)

Remove microsoft-office-2010.exe - Powered by Reason Core Security