installation.exe

File Setup LCC

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application installation.exe by File Setup LCC has been detected as adware by 4 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. The file has been seen being downloaded from oz.clickflv.com.
Publisher:
File Setup LCC  (signed and verified)

MD5:
8ca091fd7bc400e26e389e69e3a38e95

SHA-1:
18dc03f96f22de05991c5c62133c3dc29f1e06dc

SHA-256:
c346ae703ce3b09cbb9caa5e09be53bb6d366df7c79a4e535253317ca3190242

Scanner detections:
4 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
7/5/2025 4:24:10 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SoftPulse-EG [PUP]
2014.9-150220

ESET NOD32
Win32/SoftPulse.X potentially unwanted application
7.0.302.0

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.6.0

Reason Heuristics
PUP.Softpulse
15.3.1.12

File size:
1.3 MB (1,350,704 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\installation.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/16/2015 12:00:00 AM

Valid to:
2/16/2016 11:59:59 PM

Subject:
CN=File Setup LCC, O=File Setup LCC, STREET="501 Silverside Road, Suite 105", L=Wilmington, S=Delaware, PostalCode=19809, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0629F30DCECC62A8E72B47625BD36601

File PE Metadata
Compilation timestamp:
2/24/2012 7:20:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:FpL46uh+qjm+9tfI3i2OZegYRXSfoeER92B0/bJuuYLghExBjZ0y:20+99I3i2WiRgopFVuuY8hS70y

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, C0, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 36, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 84, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 18, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Entropy:
7.9738

Packer / compiler:
Nullsoft install system v2.x

Code size:
29 KB (29,696 bytes)

The file installation.exe has been seen being distributed by the following URL.

Remove installation.exe - Powered by Reason Core Security