google chrome.exe

Wizard

Volvan Premium SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application google chrome.exe by Volvan Premium SL has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. With this installer, users are expecting to download Google's Chrome web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Volvan Premium SL  (signed and verified)

Product:
Wizard

Version:
1. 9. 8. 7

MD5:
95846aa5a7cf54be5e2ae469fe8091c5

SHA-1:
20d2de27f091b3156a88040380d461887bb10f26

SHA-256:
7c7ecf6aad90acb09933d860952e3d4bd81a49945721d9326b6f289349979f07

Scanner detections:
13 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/5/2024 2:48:18 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PECompact
7.1.1

Avira AntiVirus
APPL/Softpulse.oang
7.11.189.242

avast!
Win32:SoftPulse-BJ [PUP]
141130-1

AVG
Found Win32/DH{gRIxfX5QgQd5VE8VUYEVgQkcU4ETQYEP}
2014.0.4189

Comodo Security
Application.Win32.SoftPulse.D
20266

Dr.Web
Adware.SoftPules.3
9.0.1.05190

ESET NOD32
Win32/SoftPulse.R potentially unwanted application
7.0.302.0

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.2856

McAfee
SoftPulse
5600.6928

Panda Antivirus
Trj/Genetic.gen
14.12.02.06

Qihoo 360 Security
Malware.QVM17.Gen
1.0.0.1015

Reason Heuristics
PUP.VolvanPremiumSL.N
14.12.2.18

VIPRE Antivirus
Threat.4783235
35224

File size:
1.1 MB (1,115,112 bytes)

Product version:
1. 9. 8. 7

Copyright:
Copyright (C) 2014

Original file name:
Wizard.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Language:
Spanish (Spain, International Sort)

Common path:
C:\users\{user}\downloads\google chrome.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/19/2014 7:00:00 PM

Valid to:
8/20/2015 6:59:59 PM

Subject:
CN=Volvan Premium SL, O=Volvan Premium SL, L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
248F413947247E20924C496ECEB61F8A

File PE Metadata
Compilation timestamp:
12/2/2014 10:31:00 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:Uek5eaBXlF8pV8NGpf3aG4GFbz57gdgwX+RvQJQLa4vMnhvzZF:UPlj8pI2/aGZbVgdglaQfvMZZF

Entry address:
0xCA76

Entry point:
B8, E0, 52, 58, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 72, 65, 78, 63, 6E, 67, 72, 65, 77, 34, 00, 8A, 91, 88, 95, EB, E5, F7, 2B, 5A, 3B, 01, 70, D0, AE, 9E, 2C, 74, F3, 12, 35, AC, 58, D3, 1F, 36, D9, 13, 6E, 53, 32, 16, FC, C1, EB, 25, D0, 34, 29, 8E, 0A, 1B, F5, A2, 68, 72, 8E, B9, 49, 7F, 42, 27, DF, 2F, 5D, F4, 66, 46, F2, D7, 3F, 16, 76, 6D, F8, D7, 3C, 74, 66, 4F, 6F, 28, D1, 3B, DA, B8, C0, 34, CB, 95, C2, 11, 57, 81, BA, EA, 9D, 47, 50, 69, 75, 2D, 34, 10...
 
[+]

Entropy:
7.9872  (probably packed)

Code size:
144.5 KB (147,968 bytes)

The file google chrome.exe has been seen being distributed by the following URL.

Remove google chrome.exe - Powered by Reason Core Security