player_setup.exe

Digital Plugin SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application player_setup.exe by Digital Plugin SL has been detected as adware by 26 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer.
Publisher:
Digital Plugin SL  (signed and verified)

MD5:
b1fdc0cb9baf2002548b3b29b437db71

SHA-1:
2b18465d333a216dd51a55426361bc187db6f07d

SHA-256:
9900a0887fe054c659a23ac03c609213a3248bc8022c7d18cec13038856537ce

Scanner detections:
26 / 68

Status:
Adware

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/27/2024 3:54:03 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.648094
918

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
2014.08.01

Avira AntiVirus
Adware/Softpulse.B
7.11.155.58

avast!
Win32:Adware-BRZ [PUP]
2014.9-140731

AVG
Generic
2015.0.3396

Bitdefender
Application.Generic.648094
1.0.20.1060

Clam AntiVirus
Win.Adware.Softpulse
0.98/19246

Comodo Security
Application.Win32.Softpulse.A
18483

Dr.Web
Adware.DigiPlug.1
9.0.1.0212

ESET NOD32
Win32/SoftPulse.B potentially unwanted application
8.7.0.302.0

F-Prot
W32/A-7488f3d7
v6.4.7.1.166

F-Secure
Application.Generic.648094
11.2014-31-07_5

G Data
Win32.Application.SoftPulse
14.7.24

herdProtect (fuzzy)
2014.9.10.17

IKARUS anti.virus
PUA.DigiPlug
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.1712422

McAfee
PUP-FIG!09F1C1236EF2
5600.7052

MicroWorld eScan
Application.Generic.648094
15.0.0.636

NANO AntiVirus
Riskware.Win32.DigiPlug.daxzfw
0.28.0.60253

Panda Antivirus
Trj/Genetic.gen
14.07.31.01

Reason Heuristics
PUP.Installer.DigitalPluginSL.M
14.7.31.12

Rising Antivirus
PE:Malware.SoftPulse!6.197F
23.00.65.14908

Sophos
SoftPulse
4.98

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.0

VIPRE Antivirus
Threat.4783235
30086

File size:
813.9 KB (833,448 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\player_setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/23/2014 2:00:00 AM

Valid to:
5/24/2015 1:59:59 AM

Subject:
CN=Digital Plugin SL, O=Digital Plugin SL, STREET=Calle el Pozo 17B, L=Adeje, S=Santa Cruz de Tenerife, PostalCode=38670, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C30222BF83B5AE2CB666E51380D11646

File PE Metadata
Compilation timestamp:
6/6/2014 5:51:42 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:jgQk6I6rjHaK7Ub/V798aIDFH/OakXC0aJktazsmR/sPDaY7IuT4:jg4+KU4aI+XC0X8RwvfE

Entry address:
0x4E2B0

Entry point:
E8, F3, 7A, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, 4A, 38, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, D6, 0C, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 2C, 14, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, AB, 0A, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73, 0E, E8, FB, 37, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, AD...
 
[+]

Code size:
465.5 KB (476,672 bytes)

Remove player_setup.exe - Powered by Reason Core Security