player_setup.exe

Digital Plugin SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application player_setup.exe by Digital Plugin SL has been detected as adware by 32 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer.
Publisher:
Digital Plugin SL  (signed and verified)

MD5:
34117ff2954fa018f1f5629f23aa2fbf

SHA-1:
359f161c3767c29d25c98c180fdb7017fe27b3a6

SHA-256:
b8ef64f7d627fadaa18dbda80e934bbd151dc72a42266ded66f9f1550558404c

Scanner detections:
32 / 68

Status:
Adware

Explanation:
Uses the DomainIQ download manager to bundle additional potentially unwanted software without adequate consent.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 5:39:12 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11578733
775

Agnitum Outpost
Trojan.Buzus
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
2014.12.22

Avira AntiVirus
TR/Dropper.Gen
7.11.30.172

avast!
Win32:SoftPulse-AH [PUP]
141214-1

AVG
Generic
2015.0.3253

Bitdefender
Trojan.Generic.11578733
1.0.20.1775

Clam AntiVirus
Win.Adware.MultiPlug-31138
0.98/19819

Comodo Security
Application.Win32.SoftPulse.E
20438

Dr.Web
Trojan.Packed.28257
9.0.1.05190

Emsisoft Anti-Malware
Trojan.Generic.11578733
9.0.0.4668

ESET NOD32
Win32/SoftPulse.H potentially unwanted application
7.0.302.0

Fortinet FortiGate
W32/Buzus.OVQC!tr
12/21/2014

F-Prot
W32/A-6f8f7593
v6.4.7.1.166

F-Secure
Trojan.Generic.11578733
5.13.68

G Data
Trojan.Generic.11578733
14.12.24

IKARUS anti.virus
PUA.SoftPulse
t3scan.1.8.5.0

K7 AntiVirus
Unwanted-Program
13.188.14395

Kaspersky
Trojan.Win32.Buzus
15.0.0.543

Malwarebytes
PUP.Optional.DomaIQ
v2014.12.21.10

McAfee
Program.SoftPulse
16.8.708.2

MicroWorld eScan
Trojan.Generic.11578733
15.0.0.1065

NANO AntiVirus
Trojan.Win32.MLW.dcoqvj
0.28.6.64267

Norman
Trojan.Generic.11578733
04.12.2014 14:30:06

nProtect
Trojan/W32.Buzus.1387200
14.12.19.01

Panda Antivirus
Generic Malware
14.12.21.10

Quick Heal
Trojan.Buzus.A4
12.14.14.00

Reason Heuristics
PUP.Installer.DigitalPluginSL.M
14.12.21.22

Sophos
PUA 'DomainIQ pay-per install'
5.09

Vba32 AntiVirus
Trojan.Buzus
3.12.26.3

VIPRE Antivirus
Threat.4150696
35418

Zillya! Antivirus
Trojan.Buzus.Win32.121215
2.0.0.2012

File size:
1.3 MB (1,387,200 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\super important downloads\player_setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/25/2014 5:00:00 PM

Valid to:
5/26/2015 4:59:59 PM

Subject:
CN=Digital Plugin SL, O=Digital Plugin SL, L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6B59702469CAA1B8F0FE3A86D94D6266

File PE Metadata
Compilation timestamp:
7/20/2014 3:40:01 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:jD0vT6MRnMFkDGYudfVHlG6EvJ72DgiB8mdtBA1FYTtkUnO3lOeq:SRHYlJlG1vJ720iBXzT6F3lOD

Entry address:
0x6756

Entry point:
E8, 74, 43, 00, 00, E9, 7F, FE, FF, FF, E9, B5, 13, 00, 00, FF, 35, B0, 2E, 47, 00, FF, 15, E4, 40, 41, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, 6B, 3B, 00, 00, 6A, 01, 6A, 00, E8, 82, 48, 00, 00, 83, C4, 0C, E9, 99, 48, 00, 00, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, D9, 48, 00, 00, 59, 85, C0, 74, 0F, FF, 75, 08, E8, A6, 13, 00, 00, 59, 85, C0, 74, E6, C9, C3, 6A, 01, 8D, 45, FC, 50, 8D, 4D, F0, C7, 45, FC, 74, A5, 46, 00, E8, A8, 2F, 00, 00, 68, 7C, FF, 46, 00, 8D, 45, F0, 50, C7, 45, F0, 6C, A5...
 
[+]

Entropy:
7.5798

Code size:
74.5 KB (76,288 bytes)

Remove player_setup.exe - Powered by Reason Core Security