Setup.exe

Smart Secure software SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file Setup.exe by Smart Secure software SL has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. According to AVG, this software downloads additional adware offers during setup. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
Smart Secure software SL  (signed and verified)

MD5:
03c7111959dfdc030db07df8d329869f

SHA-1:
77479f72792678ed3c2cebffa9fdb49f023cc44e

SHA-256:
e1d2ae321f3e6d37da46cce742c2ba503b65ec97e1a2e63603d6467f790a3e98

Scanner detections:
20 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/24/2024 11:19:20 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.SoftPulse.AE
6216384

Agnitum Outpost
PUA.Downloader
7.1.1

AhnLab V3 Security
PUP/Win32.SoftPulse
2015.04.09

avast!
Win32:SoftPulse-GP [PUP]
2014.9-150409

AVG
Downloader
2016.0.3145

Bitdefender
Application.Bundler.SoftPulse.AE
1.0.20.495

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.Domaiq.175
9.0.1.099

Emsisoft Anti-Malware
Application.Bundler.SoftPulse.AE
8.15.04.09.04

ESET NOD32
Win32/SoftPulse.AA potentially unwanted application
9.7.0.302.0

F-Secure
Riskware.Application.Bundler.SoftPulse
11.2015-09-04_5

G Data
Application.Bundler.SoftPulse.AE
15.4.25

K7 AntiVirus
Adware
13.202.15641

Kaspersky
not-a-virus:Downloader.Win32.DriverUpd
14.0.0.2219

Malwarebytes
PUP.Optional.DigitalPlugin.C
v2015.04.09.04

MicroWorld eScan
Application.Bundler.SoftPulse.AE
16.0.0.297

Reason Heuristics
PUP.Bundler.Softpulse
15.4.9.0

VIPRE Antivirus
Threat.4150696
38882

Zillya! Antivirus
Downloader.DriverUpd.Win32.225
2.0.0.2143

File size:
527.1 KB (539,744 bytes)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/22/2015 7:00:00 PM

Valid to:
2/23/2016 6:59:59 PM

Subject:
CN=Smart Secure software SL, O=Smart Secure software SL, STREET="El Pozo, 17", L=Adeje, S=Santa Cruz de Tenerife, PostalCode=38680, C=ES

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
695DAE5AB4D326DD6518FA7C7ABFDADA

File PE Metadata
Compilation timestamp:
4/1/2015 4:34:28 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:7xD5+98h3PcS8EJZUyLQoJcZZs5zolLjng/yMR:PY8hPcSZuyLQicZZwzwgKMR

Entry address:
0x1A13CB

Entry point:
60, E8, 00, 00, 00, 00, 58, 05, 5A, 0B, 00, 00, 8B, 30, 03, F0, 2B, C0, 8B, FE, 66, AD, C1, E0, 0C, 8B, C8, 50, AD, 2B, C8, 03, F1, 8B, C8, 57, 51, 49, 8A, 44, 39, 06, 88, 04, 31, 75, F6, 2B, C0, AC, 8B, C8, 80, E1, F0, 24, 0F, C1, E1, 0C, 8A, E8, AC, 0B, C8, 51, 02, CD, BD, 00, FD, FF, FF, D3, E5, 59, 58, 8B, DC, 8D, A4, 6C, 90, F1, FF, FF, 51, 2B, C9, 51, 51, 8B, CC, 51, 66, 8B, 17, C1, E2, 0C, 52, 57, 83, C1, 04, 51, 50, 83, C1, 04, 56, 51, E8, 5E, 00, 00, 00, 8B, E3, 5E, 5A, 2B, C0, 89, 04, 32, B4, 10...
 
[+]

Entropy:
7.9101

Packer / compiler:
ASPack v1.08.04

Code size:
1010.5 KB (1,034,752 bytes)

Remove Setup.exe - Powered by Reason Core Security