f1d8590f9ab9bfc7847008982ed18cb0.pe

SetupWizard

Volvan Premium SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file f1d8590f9ab9bfc7847008982ed18cb0.pe by Volvan Premium SL has been detected as adware by 32 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
Volvan Premium SL  (signed and verified)

Product:
SetupWizard

Description:
Setup Wizard

Version:
3.4.5.2

MD5:
f1d8590f9ab9bfc7847008982ed18cb0

SHA-1:
3c66886ed809c7413bdbb1fb651872be9bf46749

SHA-256:
238c263da97db03a4c4f71ea64f22eff9d3b4599ac3028cb9001260cd2193632

Scanner detections:
32 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 1:08:51 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.SoftPulse.F
658

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
Win-PUP/SoftPulse
2014.11.29

Avira AntiVirus
APPL/Softpulse.1014112
7.11.189.132

avast!
Win32:SoftPulse-BE [PUP]
2014.9-150418

AVG
Generic
2016.0.3136

Baidu Antivirus
PUA.Win32.SoftPulse
4.0.3.15418

Bitdefender
Application.Bundler.SoftPulse.F
1.0.20.540

Comodo Security
Application.Win32.SoftPulse.D
20225

Dr.Web
Adware.SoftPules.3
9.0.1.0108

ESET NOD32
Win32/SoftPulse.R potentially unwanted application
9.7.0.302.0

Fortinet FortiGate
Riskware/SoftPulse
4/18/2015

F-Prot
W32/S-7d1c0da9
v6.4.7.1.166

F-Secure
Application.Bundler.SoftPulse
11.2015-18-04_7

G Data
Win32.Application.SoftPulse
15.4.24

herdProtect (fuzzy)
2015.7.19.21

IKARUS anti.virus
PUA.SoftPulse
t3scan.1.8.6.0

Kaspersky
not-a-virus:AdWare.Win32.SoftPulse
14.0.0.2173

Malwarebytes
PUP.Optional.SmartSec
v2015.04.18.09

McAfee
SoftPulse
5600.6792

MicroWorld eScan
Application.Bundler.SoftPulse.F
16.0.0.324

NANO AntiVirus
Riskware.Win32.SoftPulse.djopku
0.30.0.64812

nProtect
Trojan-Clicker/W32.SoftPulse.983520
15.01.22.01

Panda Antivirus
Trj/Genetic.gen
15.04.18.09

Qihoo 360 Security
HEUR/QVM17.0.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Softpulse.Bundler
15.4.18.5

Sophos
SoftPulse
4.98

Trend Micro House Call
TROJ_GEN.F0C2C00AC15
7.2.108

Trend Micro
TROJ_GEN.F0C2C00AC15
10.465.18

Vba32 AntiVirus
Downloader.Agent
3.12.26.3

VIPRE Antivirus
Threat.4783235
35224

Zillya! Antivirus
Adware.SoftPulse.Win32.16
2.0.0.2042

File size:
960.5 KB (983,520 bytes)

Product version:
3.4.5.2

Copyright:
Copyright (C) 2014

Original file name:
SetupWizard.exe

Bundler/Installer:
Softpulse SoftwareBundler

Language:
Spanish (Spain, International Sort)

Common path:
C:\users\{user}\downloads\f1d8590f9ab9bfc7847008982ed18cb0.pe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/19/2014 5:00:00 PM

Valid to:
8/20/2015 4:59:59 PM

Subject:
CN=Volvan Premium SL, O=Volvan Premium SL, L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
248F413947247E20924C496ECEB61F8A

File PE Metadata
Compilation timestamp:
11/28/2014 4:52:44 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:oob9GXioEE6FY5fQ5emJYeXOxXzF6oHU9gfE:oohGXiBE6FY1ps656tg8

Entry address:
0x118E6

Entry point:
B8, 30, F2, 56, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 2A, FB, B6, 3A, 1C, 64, E5, 8A, D4, C7, FD, 61, 8E, E7, E8, E9, B4, 0A, 4C, 91, E3, 22, 20, 39, CE, 45, CE, CE, D5, D6, F9, 25, BA, 89, 97, 3F, 4A, 32, 73, 92, 1D, B4, B7, 8A, F2, 3B, 40, A1, 0F, E4, 3F, D9, FE, 2B, 6B, B2, B7, A5, 26, 45, CE, 8D, E0, 84, 93, B3, 69, C6, 53, 90, 23, 6D, D5, 49, CE, 85, 4B, 61, DE, F6, 6E, 89, 8A, CA, BC, 33, 93, 9E, E5, F0, CE, 8F, 6E...
 
[+]

Entropy:
7.9777

Packer / compiler:
PECompact v2

Code size:
155 KB (158,720 bytes)

Remove f1d8590f9ab9bfc7847008982ed18cb0.pe - Powered by Reason Core Security