setup.exe

Softpulse SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Softpulse SL has been detected as adware by 25 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. It is also typically executed from an Internet Explorer cache folder.
Publisher:
Softpulse SL  (signed and verified)

MD5:
d2fcdd42460bce0d9d981d4201dd3614

SHA-1:
02f90cd996e90d83ba35d0845d77ce44c87e4b4d

SHA-256:
9926d048cb6373938f902ac06da5ed7eda99241ebefeb3086f1d6a92fd6a5196

Scanner detections:
25 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/20/2024 12:50:14 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.DomaIQ.14
922

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
2014.07.28

Avira AntiVirus
APPL/Bundler.DomaIQ.14
7.11.164.60

avast!
Win32:SoftPulse-H [PUP]
140617-1

AVG
Generic
2015.0.3400

Bitdefender
Gen:Variant.Application.Bundler.DomaIQ.14
1.0.20.1045

Clam AntiVirus
Win.Trojan.Agent-751935
0.98/21411

Comodo Security
Application.Win32.DomaIQ.SPL
18997

Dr.Web
Trojan.Packed.28234
9.0.1.05190

ESET NOD32
Win32/SoftPulse.F potentially unwanted application
7.0.302.0

F-Prot
W32/A-b3d35873
v6.4.7.1.166

F-Secure
Gen:Variant.Application.Bundler
11.2014-28-07_2

G Data
Gen:Variant.Application.Bundler.DomaIQ.14
14.7.24

IKARUS anti.virus
PUA.SoftPulse
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.181.12846

Malwarebytes
PUP.Optional.DomaIQ
v2014.07.28.08

McAfee
SoftPulse
5600.7056

MicroWorld eScan
Gen:Variant.Application.Bundler.DomaIQ.14
15.0.0.627

NANO AntiVirus
Trojan.Win32.Agent.dcekir
0.28.2.60990

Panda Antivirus
Trj/Genetic.gen
14.07.28.08

Reason Heuristics
PUP.Installer.SoftpulseSL.F
14.7.28.8

Sophos
SoftPulse
4.98

Vba32 AntiVirus
Downloader.Agent
3.12.26.3

VIPRE Antivirus
Threat.4150696
31208

File size:
1.2 MB (1,260,832 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\setup.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/11/2014 4:48:56 PM

Valid to:
2/12/2015 4:48:56 PM

Subject:
CN=Softpulse SL, O=Softpulse SL, L=Guia de Isora, S=Tenerife, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11210602DAEE0BE4AA7D855EE48D3D77A3CC

File PE Metadata
Compilation timestamp:
7/1/2014 3:34:09 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:xWLjWdykSBLgdNxJMfonoUT6pXGZWRW7MG/RMZZe22Ue212:xgzWdNonUT4+MR6

Entry address:
0x80AC

Entry point:
E8, 66, 61, 00, 00, E9, 39, FE, FF, FF, E9, ED, 49, 00, 00, FF, 35, 80, A0, 43, 00, FF, 15, 24, 61, 42, 00, C3, FF, 35, 80, A0, 43, 00, FF, 15, 24, 61, 42, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, C3, 58, 00, 00, 6A, 01, 6A, 00, E8, 4F, 68, 00, 00, 83, C4, 0C, E9, 66, 68, 00, 00, 55, 8B, EC, 56, FF, 35, 80, A0, 43, 00, FF, 15, 24, 61, 42, 00, FF, 75, 08, 8B, F0, FF, 15, 20, 61, 42, 00, A3, 80, A0, 43, 00, 8B, C6, 5E, 5D, C3, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, A3, 6A, 00, 00, 59, 85, C0, 74, 0F...
 
[+]

Entropy:
7.5912

Code size:
148 KB (151,552 bytes)

Remove setup.exe - Powered by Reason Core Security