setup.exe

Digital Plugin S.l.

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Digital Plugin S.l has been detected as adware by 35 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent.
Publisher:
Digital Plugin S.l.  (signed and verified)

MD5:
e1bb09f2f232029566587a517a283696

SHA-1:
aafbdb8d2e0210972ed8e432d62338bb9ce1bc8a

SHA-256:
6019d06270f9d23ec08410b0449f791cb75d0817dede7bd76f883f2239cff04c

Scanner detections:
35 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/16/2024 9:31:39 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.SoftPulse.P
5650986

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
2014.08.06

Avira AntiVirus
TR/Dropper.Gen
7.11.30.172

avast!
Win32:Dropper-gen [Drp]
2014.9-150421

AVG
Generic
2016.0.3133

Bitdefender
Application.Bundler.SoftPulse.P
1.0.20.555

Clam AntiVirus
Win.Adware.MultiPlug-31138
0.98/21511

Comodo Security
Application.Win32.SoftPulse.G
21841

Dr.Web
Adware.SoftPules.3, Trojan.DownLoader11.32266
9.0.1.05190

Emsisoft Anti-Malware
Application.Bundler.SoftPulse.P
9.0.0.4799

ESET NOD32
Win32/SoftPulse (variant)
9.10187

Fortinet FortiGate
W32/Buzus.QBNO!tr
4/21/2015

F-Prot
W32/A-93d66bbd
v6.4.7.1.166

F-Secure
Riskware.Application.Bundler.SoftPulse
5.13.68

G Data
Application.Bundler.SoftPulse
15.4.25

herdProtect (fuzzy)
2015.7.22.12

K7 AntiVirus
Unwanted-Program
13.202.15654

Kaspersky
not-a-virus:AdWare.Win32.SoftPulse
15.0.0.543

Malwarebytes
PUP.Optional.BundleInstaller.A
v2015.04.21.04

McAfee
Socrydo
5600.6789

MicroWorld eScan
Application.Bundler.SoftPulse.P
16.0.0.333

NANO AntiVirus
Riskware.Win32.Agent.ddtkxp
0.30.20.1219

Norman
Gen:Variant.Adware.Graftor.150962
03.12.2014 13:20:04

nProtect
Trojan-Clicker/W32.SoftPulse.1249856
15.04.20.01

Panda Antivirus
Trj/Genetic.gen
15.04.21.04

Quick Heal
Trojan.Buzus.A4
4.15.14.00

Reason Heuristics
Threat.Softpulse.Bundler
15.4.21.0

Rising Antivirus
PE:Trojan.Dropper!6.1D08
23.00.65.15419

Sophos
SoftPulse
4.98

Trend Micro House Call
ADW_PULSOFT.SM
7.2.111

Trend Micro
ADW_PULSOFT.SM
10.465.21

Vba32 AntiVirus
Trojan.Buzus
3.12.26.3

VIPRE Antivirus
Threat.4783235
31208

Zillya! Antivirus
Trojan.Inject.Win32.80646
2.0.0.2145

File size:
1.2 MB (1,249,856 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/13/2014 8:00:00 PM

Valid to:
7/14/2015 7:59:59 PM

Subject:
CN=Digital Plugin S.l., O=Digital Plugin S.l., L=Guia de Isora, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
229111B20CCF13394E8E6CA9EAB4121F

File PE Metadata
Compilation timestamp:
7/31/2014 6:03:44 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:g9W0LXXy9G36xN9G36xtkxsSU7uk8tr6abL3ARQx0PrHglCcmrnE/mSNZAglsl:EWq35Lxs5yvP3uSmrnE/mSZU

Entry address:
0x5F90

Entry point:
E8, 0F, 20, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 8B, 45, 0C, 83, EC, 20, 56, 57, 6A, 08, 59, BE, 10, 20, 41, 00, 8D, 7D, E0, F3, A5, 8B, 4D, 08, 5F, 5E, 85, C0, 74, 0D, F6, 00, 10, 74, 08, 8B, 01, 8B, 40, FC, 8B, 40, 18, 89, 4D, F8, 89, 45, FC, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, AC, 10, 41, 00, C9, C2, 08, 00, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 8B, 4D, EC, 33, CD, E8, 36...
 
[+]

Entropy:
7.7157  (probably packed)

Code size:
63 KB (64,512 bytes)

Remove setup.exe - Powered by Reason Core Security