setup.exe

Softpulse SLU

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Softpulse SLU has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer.
Publisher:
Softpulse SLU  (signed and verified)

MD5:
2a31e4a5b8df1a79c7dff2b799978f9a

SHA-1:
c0cbd347f6fd576c282c4a670951d38259b20f5b

SHA-256:
3af0460503165b501404a0508a84388464e2ab908001773b4a3cd1c13e2fb414

Scanner detections:
13 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/20/2024 5:24:29 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
TR/Dropper.Gen
7.11.30.172

avast!
Win32:PUP-gen [PUP]
2014.9-140731

AVG
Generic
2015.0.3400

ESET NOD32
Win32/SoftPulse (variant)
8.10161

IKARUS anti.virus
PUA.SoftPulse
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.181.12898

McAfee
Socrydo
5600.7056

Panda Antivirus
Trj/Genetic.gen
14.07.28.01

Reason Heuristics
PUP.Installer.SoftpulseSLU.F
14.7.28.0

Sophos
SoftPulse
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Skwink
10449

VIPRE Antivirus
Threat.4150696
31208

File size:
1.3 MB (1,364,840 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
2/11/2014 1:24:30 PM

Valid to:
2/11/2015 1:24:30 PM

Subject:
CN=Softpulse SLU, O=Softpulse SLU, L=Guia de Isora, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
03F6DB66AAA548

File PE Metadata
Compilation timestamp:
7/26/2014 8:35:00 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:jbnzd/8NTSOnB257prp2Aj2zapBn5pBN95A61puc0NAvAYDhptl:rjT57Bbt7nH7uc0+vtPb

Entry address:
0x6586

Entry point:
E8, 74, 43, 00, 00, E9, 7F, FE, FF, FF, E9, B5, 13, 00, 00, FF, 35, 10, 6D, 46, 00, FF, 15, CC, 40, 41, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, 6B, 3B, 00, 00, 6A, 01, 6A, 00, E8, 82, 48, 00, 00, 83, C4, 0C, E9, 99, 48, 00, 00, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, D9, 48, 00, 00, 59, 85, C0, 74, 0F, FF, 75, 08, E8, A6, 13, 00, 00, 59, 85, C0, 74, E6, C9, C3, 6A, 01, 8D, 45, FC, 50, 8D, 4D, F0, C7, 45, FC, A4, E1, 45, 00, E8, A8, 2F, 00, 00, 68, 80, 3B, 46, 00, 8D, 45, F0, 50, C7, 45, F0, 9C, E1...
 
[+]

Code size:
74 KB (75,776 bytes)

Remove setup.exe - Powered by Reason Core Security