Setup.exe

PLUGIN UPDATE S.L

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file Setup.exe by PLUGIN UPDATE S.L has been detected as adware by 25 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
PLUGIN UPDATE S.L  (signed and verified)

MD5:
b9dd7e539d336a9b3bb6b2f3eb797c2e

SHA-1:
112b9e9393c6ebf5aa6d131a4dbba2f3298a4211

SHA-256:
7899d82ffa4f8582211a2dc236a032b2a47f8dc371f8dd1f7439b8e5595eb33b

Scanner detections:
25 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/27/2024 1:28:37 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.83505
5690745

Agnitum Outpost
PUA.Downloader
7.1.1

AhnLab V3 Security
PUP/Win32.SoftPulse
2015.04.15

Avira AntiVirus
PUA/Softpulse.Gen
3.6.1.96

AVG
Win.Threat.Medium
2014.0.4311

Bitdefender
Gen:Variant.Strictor.83505
1.0.20.575

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.Domaiq.219
9.0.1.0115

Emsisoft Anti-Malware
Gen:Variant.Strictor.83505
8.15.04.25.03

ESET NOD32
Win32/SoftPulse.AE potentially unwanted application
9.7.0.302.0

Fortinet FortiGate
Riskware/SoftPulse
4/25/2015

F-Prot
W32/SoftPulse.D2.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Strictor.83505
5.13.68

G Data
Gen:Variant.Strictor.83505
15.4.25

herdProtect (fuzzy)
2015.7.26.5

IKARUS anti.virus
PUA.SoftPulse
t3scan.1.8.9.0

K7 AntiVirus
Unwanted-Program
13.203.15707

Kaspersky
not-a-virus:Downloader.Win32.DriverUpd
14.0.0.2139

McAfee
Program.SoftPulse
16.8.708.2

MicroWorld eScan
Gen:Variant.Strictor.83505
16.0.0.345

NANO AntiVirus
Trojan.Win32.DriverUpd.dqjpjf
0.30.16.1110

Panda Antivirus
Trj/Genetic.gen
15.04.25.03

Reason Heuristics
Threat.Softpulse.Bundler
15.4.24.23

VIPRE Antivirus
Threat.4150696
39676

Zillya! Antivirus
Backdoor.PePatch.Win32.70376
2.0.0.2153

File size:
669 KB (685,016 bytes)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
Starfield Technologies, Inc.

Valid from:
7/22/2014 9:14:26 PM

Valid to:
7/22/2015 9:14:26 PM

Subject:
CN=PLUGIN UPDATE S.L, O=PLUGIN UPDATE S.L, L=GUIA DE ISORA, C=ES

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
079EA58C1A6ED1

File PE Metadata
Compilation timestamp:
4/10/2015 6:34:03 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:SDdnl3/7POmBrd1XyE+zlM78D6Jcp1dWBByZGnuhtVuxmCXi8dNba:CdnlPtr/jalw8Dsn2UnsVimSiwNe

Entry address:
0x1E1070

Entry point:
60, BE, 00, 50, 54, 00, 8D, BE, 00, C0, EB, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8404

Packer / compiler:
UPX 2.90LZMA

Code size:
628 KB (643,072 bytes)

Remove Setup.exe - Powered by Reason Core Security