setup.exe

Setup Manager LLC

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Setup Manager has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. The file has been seen being downloaded from www.chromemore.com.
Publisher:
Setup Manager LLC  (signed and verified)

MD5:
e1bc9af23f5fd32d7f4be35142380995

SHA-1:
e538547210ab9fac6b134550c87b6415ad4b113a

SHA-256:
814a8a7a7333db77a2c8ef40ae9b9d2b6c81f773ecb64a4f2bb8e201cc4fbb16

Scanner detections:
7 / 68

Status:
Adware

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/25/2024 7:52:51 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PECompact
7.1.1

Avira AntiVirus
PUA/Softpulse.Gen
7.11.212.228

ESET NOD32
Win32/SoftPulse.X potentially unwanted application
7.0.302.0

Kaspersky
not-a-virus:Downloader.Win32.DriverUpd
15.0.0.543

Panda Antivirus
Trj/Genetic.gen
15.02.27.09

Reason Heuristics
PUP.Bundler.Softpulse
15.3.11.17

VIPRE Antivirus
Threat.4150696
37588

File size:
557.1 KB (570,496 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/16/2015 10:00:00 AM

Valid to:
2/17/2016 9:59:59 AM

Subject:
CN=Setup Manager LLC, O=Setup Manager LLC, STREET="501 Silverside Road, Suite 105", L=Wilmington, S=Delaware, PostalCode=19809, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0083BDD227DBB7AC8288AA961219124A1B

File PE Metadata
Compilation timestamp:
2/27/2015 7:59:14 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:3X00SzoeqTYUcGhGQoXvMhUB0xTAmeg8IHXhS:H0jzoDwcJoXeUB0xTAsr

Entry address:
0x1000

Entry point:
B8, 24, D9, 58, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 21, B2, FF, 75, 14, 10, 74, 31, 2D, 38, 0C, 08, E8, 7A, DB, B5, 1D, 72, 01, 08, 83, C4, 10, 02, 00, A8, C3, 47, 6B, 56, 57, 8B, F9, 8B, 37, 85, F6, 74, 3C, 83, 3E, FD, 74, 37, CD, 02, 00, C4, 00, 74, 13, 8B, 06, 3B, C7, 74, 08, 8D, 70, 04, C0, 02, 11, 8B, 75, F2, 17, 68, BD, 00, B0, 1E, C4, 02, 68, 58, 3B, 4F, 24, 00, 80, 7F, 81, 09, E3, FB, 0C, 8B, 47, 04, 89, 06, 83...
 
[+]

Entropy:
7.8876

Packer / compiler:
PECompact v2

Code size:
965.5 KB (988,672 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security