setup.exe

Smart Secure software SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Smart Secure software SL has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer.
Publisher:
Smart Secure software SL  (signed and verified)

MD5:
37a83b275b02afee9edaaa3ec68553fd

SHA-1:
463d31992f3457e30f9a2d6b96913abae149a716

SHA-256:
74a61553cc67bd0d8032f93fb18a3b4a481674730dc81cfa138d33e8c11b7721

Scanner detections:
11 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/25/2024 3:43:31 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.SoftPulse
2015.05.31

Avira AntiVirus
PUA/Softpulse.Gen
8.3.1.6

AVG
Adware AdPlugin.DAT
2014.0.4311

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.Domaiq.175
9.0.1.05190

ESET NOD32
Win32/SoftPulse.X potentially unwanted application
7.0.302.0

IKARUS anti.virus
PUA.SoftPulse
t3scan.1.9.2.0

NANO AntiVirus
Trojan.Win32.Domaiq.dpomrw
0.30.24.1636

Reason Heuristics
PUP.Softpulse.Bundler
15.5.30.17

VIPRE Antivirus
Threat.4150696
40552

File size:
1.3 MB (1,359,992 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/22/2015 5:00:00 PM

Valid to:
2/23/2016 4:59:59 PM

Subject:
CN=Smart Secure software SL, O=Smart Secure software SL, STREET="El Pozo, 17", L=Adeje, S=Santa Cruz de Tenerife, PostalCode=38680, C=ES

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
695DAE5AB4D326DD6518FA7C7ABFDADA

File PE Metadata
Compilation timestamp:
3/9/2015 4:50:16 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:iZNzx7jam3NkiOTrK5PZEvX+cEuJqQVmXIXBwh5uOezdOSqIpquDwfEfFFmIvaxr:iZNzVj9NOTrKZmvX+cLVm8MOdOSPB0oK

Entry address:
0x1000

Entry point:
B8, 54, 6C, 90, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 62, E3, FF, F2, 24, 85, E0, 4B, 9C, 44, DF, 4B, FB, E9, 84, 9E, 7C, 19, 7F, 90, F3, 90, 7D, 59, 3E, 23, 92, 98, EB, B3, 21, 00, 4C, 9E, 61, 63, 69, 77, 94, 29, 14, 10, D6, 9F, 55, 74, 64, 7C, 06, 1E, 12, 17, 2B, E7, 82, 69, B2, 53, 20, DD, F4, C3, EE, 5B, 1C, 85, 14, 0A, 54, B2, FD, 6C, 7B, 0A, 9A, 19, F9, C8, E9, 93, 99, F3, EC, 4D, 00, 64, EC, 09, DB, 6C, 2A, E4, 64...
 
[+]

Entropy:
7.9853

Packer / compiler:
PECompact v2

Code size:
3.7 MB (3,851,776 bytes)

Remove setup.exe - Powered by Reason Core Security