Setup.exe

Soft

Darwen Marketing Inc.

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The file Setup.exe, “Soft Setup ” by Darwen Marketing has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
Program   (signed by Darwen Marketing Inc.)

Product:
Soft

Description:
Soft Setup

Version:
4.7.2.0

MD5:
d80026b1c05825df630910644ed49e12

SHA-1:
cf191b3efbbc63c17925d3301be66b4b43e6e26e

SHA-256:
14e0a5bcf5c332e3247ba27cbc9790d10638dc2afe644ef7c0c0a5093c49eb15

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/25/2024 1:36:48 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
InstallCore
2016.0.3158

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.1572

ESET NOD32
Win32/InstallCore.YL potentially unwanted application
9.7.0.302.0

Reason Heuristics
PUP.Bundler.installCore
15.3.27.8

VIPRE Antivirus
Threat.4786018
38950

File size:
684.5 KB (700,896 bytes)

Product version:
1.1

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
1/7/2015 12:00:00 AM

Valid to:
1/7/2016 11:59:59 PM

Subject:
CN=Darwen Marketing Inc., OU=IT, O=Darwen Marketing Inc., L=Victoria, S=British Columbia, C=CA

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
4F7ED3E5324494326CB1FB18C4370F32

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:q5BGhCM5PtTMid8VEVubwRpN3sDZXxqEFAJ2w/L3n1bAJ7P8nJ5/VyRA5P:q5Bop5FMijubwfNGhqF8iL3n1OEnJ5UM

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.8943

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

Remove Setup.exe - Powered by Reason Core Security