setup.exe

SOFTPULSE S.L.

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by SOFTPULSE S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Softpulse SoftwareBundler installer.
Publisher:
SOFTPULSE S.L.  (signed and verified)

MD5:
8f838df086b37a179beac9537874fca9

SHA-1:
511c205d60e52ad061229b5162cbe62a37272618

SHA-256:
8529e1baceb5b73b16575ff293b2c74fb2206ea41bbc256f00b702c7df68ff5c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/24/2024 3:08:23 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softpulse (M)
17.3.1.12

File size:
548.5 KB (561,688 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
7/8/2014 11:13:26 AM

Valid to:
7/8/2015 11:13:26 AM

Subject:
CN=SOFTPULSE S.L., O=SOFTPULSE S.L., L=Guia de Isora, C=ES

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B582684D0A7AC

File PE Metadata
Compilation timestamp:
3/26/2015 10:49:32 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1E3F00

Entry point:
60, BE, 00, 60, 56, 00, 8D, BE, 00, B0, E9, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 29, 15, 1E, 00, 57, 83, C3, 04, 53, 68, FA, DE, 07, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
508 KB (520,192 bytes)

Remove setup.exe - Powered by Reason Core Security