player_setup.exe

Digital Plugin SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application player_setup.exe by Digital Plugin SL has been detected as adware by 22 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
Digital Plugin SL  (signed and verified)

MD5:
45cd868953cd4e8ac3da314b8427780b

SHA-1:
a4881b4b72d2e346adb4ab04b5340eef32c0ffa1

SHA-256:
9bf35f40c37694f670b82722293a43eba16e23fcf82e7f404b0f9f939f540785

Scanner detections:
22 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/20/2024 1:10:30 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.DomaIQ.15
886

AhnLab V3 Security
PUP/Win32.DomaIQ
2014.09.02

Avira AntiVirus
APPL/Downloader.Gen8
7.11.170.102

avast!
Win32:SoftPulse-A [PUP]
140813-1

AVG
Win.Threat.High
2014.0.4015

Baidu Antivirus
Adware.Win32.SoftPulse
4.0.3.1491

Bitdefender
Gen:Variant.Application.Bundler.DomaIQ.15
1.0.20.1220

Clam AntiVirus
Win.Trojan.Inject-10285
0.98/19318

Dr.Web
Adware.Downware.5055
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.DomaIQ.15
9.0.0.4324

ESET NOD32
Win32/SoftPulse.D potentially unwanted application
7.0.302.0

F-Prot
W32/A-902f6035
v6.4.7.1.166

G Data
Gen:Variant.Application.Bundler.DomaIQ.15
14.9.24

IKARUS anti.virus
Trojan.Inject
t3scan.1.7.5.0

K7 AntiVirus
Unwanted-Program
13.183.13230

Kaspersky
Trojan.Win32.Inject
15.0.0.463

NANO AntiVirus
Trojan.Win32.Inject.dbobdv
0.28.2.61942

Norman
Malware
11.20140901

nProtect
Trojan/W32.Inject.1245720
14.09.01.01

Reason Heuristics
PUP.Installer.DigitalPluginSL.M
14.9.1.19

VIPRE Antivirus
Threat.4150696
32210

Zillya! Antivirus
Trojan.Inject.Win32.75845
2.0.0.1908

File size:
1.2 MB (1,245,720 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\player_setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/22/2014 9:00:00 PM

Valid to:
5/23/2015 8:59:59 PM

Subject:
CN=Digital Plugin SL, O=Digital Plugin SL, STREET=Calle el Pozo 17B, L=Adeje, S=Santa Cruz de Tenerife, PostalCode=38670, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C30222BF83B5AE2CB666E51380D11646

File PE Metadata
Compilation timestamp:
6/13/2014 12:15:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:NhRyk5BKO3gux5cGnWYu2qR3Jai7r9rfPn9vYjzNJJJJJJJJJJJJJ7JJJJJOnOn1:Nh4qvQImGWYu2w7Nmn5

Entry address:
0x3B5D

Entry point:
E8, 7F, 38, 00, 00, E9, 39, FE, FF, FF, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 5F, 00, 00, 00, C7, 06, 5C, BA, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 5F, 00, 00, 00, C7, 06, 5C, BA, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, A0, 00, 00, 00, C7, 06, 44, BA, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 44, 00, 00, 00, C7, 06, 44, BA, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1...
 
[+]

Code size:
100 KB (102,400 bytes)

The file player_setup.exe has been seen being distributed by the following URL.

Remove player_setup.exe - Powered by Reason Core Security