setupwizard.exe

Smart Secure Software S.l.

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setupwizard.exe by Smart Secure Software S.l has been detected as adware by 23 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
Smart Secure Software S.l.  (signed and verified)

Version:
2.20.30.11

MD5:
9de8ec494a6c13fb830239f4e321125d

SHA-1:
a4505c652e71c34f47b2cd417f496d0c449d2467

SHA-256:
bcf32d99a83367920c3ac33caea11fd6a99d764afca9ecb2120f747f2165a0ad

Scanner detections:
23 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 1:49:30 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.SoftPulse.2
839

AhnLab V3 Security
Win-PUP/DomaIQ.Gen
2014.10.18

Avira AntiVirus
APPL/Bundler.20
7.11.179.120

avast!
Win32:GenMalicious-ADB [PUP]
2014.9-141019

AVG
Generic
2015.0.3317

Baidu Antivirus
PUA.Win32.SoftPulse
4.0.3.141018

Bitdefender
Gen:Variant.Application.Bundler.SoftPulse.2
1.0.20.1455

Dr.Web
Trojan.DownLoader11.36367
9.0.1.0292

ESET NOD32
Win32/SoftPulse (variant)
8.10580

Fortinet FortiGate
Riskware/SoftPulse
10/18/2014

F-Secure
Gen:Variant.Application.Bundler
11.2014-18-10_7

G Data
Gen:Variant.Application.Bundler.SoftPulse
14.10.24

K7 AntiVirus
Unwanted-Program
13.184.13718

Kaspersky
Trojan.Win32.Inject
14.0.0.3082

Malwarebytes
PUP.Optional.DomaIQ
v2014.10.19.09

McAfee
Artemis!9DE8EC494A6C
5600.6973

MicroWorld eScan
Gen:Variant.Application.Bundler.SoftPulse.2
15.0.0.873

NANO AntiVirus
Trojan.Win32.Agent.dguxty
0.28.2.62671

Norman
Kryptik.CDHN
11.20141018

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.SmartSecureSoftwareSl.L
14.10.18.15

Sophos
Smart Secure Software
4.98

VIPRE Antivirus
DomaIQ
34014

File size:
1.2 MB (1,247,512 bytes)

Product version:
2.20.30.11

Copyright:
Copyright (C) 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Language:
English

Common path:
C:\users\{user}\appdata\local\apps\2.0\74thbybo.tey\po7tte89.tkv\setu...app_c1f3359fdcaf15c3_0001.0000_9e653882c139fff6\setupwizard.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/17/2014 1:00:00 AM

Valid to:
6/18/2015 12:59:59 AM

Subject:
CN=Smart Secure Software S.l., O=Smart Secure Software S.l., L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
47353B4EEC0D902A135E20BEE1A66817

File PE Metadata
Compilation timestamp:
10/16/2014 3:24:10 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:80bk5L1+miBQxprjUQftJLpV1VnaLcpI4Ig+JxXZ:801mvxD3pRaLcZIg+F

Entry address:
0x7BA7

Entry point:
E8, DC, 40, 00, 00, E9, 7F, FE, FF, FF, E9, B5, 26, 00, 00, FF, 35, 40, FD, 44, 00, FF, 15, C8, 60, 41, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, D3, 38, 00, 00, 6A, 01, 6A, 00, E8, 7D, 47, 00, 00, 83, C4, 0C, E9, 94, 47, 00, 00, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, D4, 47, 00, 00, 59, 85, C0, 74, 0F, FF, 75, 08, E8, A7, 2B, 00, 00, 59, 85, C0, 74, E6, C9, C3, 6A, 01, 8D, 45, FC, 50, 8D, 4D, F0, C7, 45, FC, 94, 63, 44, 00, E8, 4E, 2F, 00, 00, 68, EC, C7, 44, 00, 8D, 45, F0, 50, C7, 45, F0, 8C, 63...
 
[+]

Entropy:
7.5216

Code size:
81.5 KB (83,456 bytes)

Remove setupwizard.exe - Powered by Reason Core Security