google chrome.exe

Volvan Premium SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application google chrome.exe by Volvan Premium SL has been detected as adware by 26 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. With this installer, users are expecting to download Google's Chrome web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Volvan Premium SL  (signed and verified)

MD5:
5c3a18fac0d3590654bec0053d55fa49

SHA-1:
b41d2a294be3e65372a88a65101ec5eab07f6185

SHA-256:
3e0e5c44cdfa390ff977c29589c75e4a7dd47867a7888f827bfe47327068b65b

Scanner detections:
26 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
2/27/2025 2:02:59 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.SoftPulse.4
811

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
Win-PUP/SoftPulse
2014.11.10

Avira AntiVirus
TR/Dropper.Gen
7.11.30.172

avast!
Win32:Malware-gen
141025-0

AVG
Generic
2015.0.3289

Bitdefender
Gen:Variant.Application.Bundler.SoftPulse.4
1.0.20.1600

Clam AntiVirus
Win.Trojan.Softpulse-74
0.98/21411

Dr.Web
Adware.Downware.9039
9.0.1.05190

ESET NOD32
Win32/SoftPulse (variant)
8.10697

Fortinet FortiGate
W32/AntiAV.LGC!tr
11/16/2014

F-Prot
W32/A-3b323074
v6.4.7.1.166

F-Secure
Gen:Variant.Application.Bundler
11.2014-16-11_1

G Data
Gen:Variant.Application.Bundler.SoftPulse
14.11.24

K7 AntiVirus
Unwanted-Program
13.185.13943

Kaspersky
not-a-virus:Downloader.Win32.DriverUpd
14.0.0.2938

Malwarebytes
PUP.Optional.DomaIQ
v2014.11.16.10

McAfee
Socrydo
5600.6945

MicroWorld eScan
Gen:Variant.Application.Bundler.SoftPulse.4
15.0.0.960

NANO AntiVirus
Trojan.Win32.DriverUpd.dilccw
0.28.6.62995

Panda Antivirus
Trj/Genetic.gen
14.11.16.10

Reason Heuristics
Threat.Win.Reputation.IMP
14.11.16.10

Sophos
SoftPulse
4.98

Vba32 AntiVirus
Signed-Adware.Softpulse
3.12.26.3

VIPRE Antivirus
Threat.4150696
34232

Zillya! Antivirus
Adware.SoftPulse.Win32.9
2.0.0.1983

File size:
958.3 KB (981,344 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\google chrome.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/20/2014 2:00:00 AM

Valid to:
8/21/2015 1:59:59 AM

Subject:
CN=Volvan Premium SL, O=Volvan Premium SL, L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
248F413947247E20924C496ECEB61F8A

File PE Metadata
Compilation timestamp:
11/7/2014 4:27:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:79+z4WWD6/G3a72nsZTHZROn7MjX/C++u0+jJhkCad:79+z4Witq7IGZRO7oXD0+1hwd

Entry address:
0x136F6

Entry point:
E8, BD, 79, 00, 00, E9, 7F, FE, FF, FF, E9, C0, 10, 00, 00, 3B, 0D, 70, 18, 49, 00, 75, 02, F3, C3, E9, C2, 7B, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00...
 
[+]

Code size:
172.5 KB (176,640 bytes)

The file google chrome.exe has been seen being distributed by the following URL.

Remove google chrome.exe - Powered by Reason Core Security