setup.exe

Wizard

Yumon System SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Yumon System SL has been detected as adware by 35 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. The file has been seen being downloaded from www.worksdown.com.
Publisher:
Yumon System SL  (signed and verified)

Product:
Wizard

Version:
1. 9. 8. 7

MD5:
5fd484337440187407aa7b55c9644f48

SHA-1:
8c2f1eb5184350e5692c6594feace70ab5067eb1

SHA-256:
7a44c8d2d89bd5479374d18be5e779540db2fc2e47f694c16f3df0f1a74db796

Scanner detections:
35 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/28/2024 1:27:48 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Zusy.117871
360

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
Win-PUP/SoftPulse
2014.11.29

Avira AntiVirus
APPL/Softpulse.1014112
7.11.189.122

avast!
Win32:SoftPulse-BE [PUP]
2014.9-160210

AVG
Found Win32/DH{gRIxfX5QgQd5VE8VUYEVgQkcU4ETQYEP}
2017.0.2838

Bitdefender
Gen:Variant.Graftor.165890
1.0.20.205

Clam AntiVirus
Win.Adware.MultiPlug-31138
0.98/19817

Comodo Security
Application.Win32.SoftPulse.D
20283

Dr.Web
Adware.SoftPules.3
9.0.1.041

Emsisoft Anti-Malware
Gen:Variant.Adware.Zusy.117871
8.16.02.10.09

ESET NOD32
Win32/SoftPulse.P potentially unwanted application
10.7.0.302.0

Fortinet FortiGate
W32/Kryptik.BWOY!tr
2/10/2016

F-Prot
W32/A-3f31f6a7
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Zusy.117871
11.2016-10-02_4

G Data
Win32.Application.SoftPulse
16.2.24

IKARUS anti.virus
not-a-virus:AdWare.SoftPulse
t3scan.1.8.5.0

K7 AntiVirus
Unwanted-Program
13.186.14239

Kaspersky
Trojan.Win32.Buzus
14.0.0.683

Malwarebytes
PUP.Optional.SmartSec
v2016.02.10.09

McAfee
Program.SoftPulse
5600.6494

MicroWorld eScan
Gen:Variant.Graftor.165890
17.0.0.123

NANO AntiVirus
Trojan.Win32.DriverUpd.djmoky
0.28.6.63726

Norman
Gen:Variant.Adware.Zusy.117871
11.20160210

nProtect
Trojan/W32.Buzus.1348032
15.01.07.01

Panda Antivirus
Trj/Genetic.gen
16.02.10.09

Qihoo 360 Security
Malware.QVM18.Gen
1.0.0.1015

Reason Heuristics
PUP.Softpulse.YumonSystem.Bundler (M)
16.2.10.9

Rising Antivirus
PE:Trojan.Win32.Buzus.fyw!1075356101
23.00.65.16208

Sophos
SoftPulse
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
9332

Trend Micro House Call
TROJ_GEN.R047B01L914
7.2.41

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Threat.5064683
35418

Zillya! Antivirus
Adware.Agent.Win32.25201
2.0.0.2006

File size:
1.3 MB (1,348,040 bytes)

Product version:
1. 9. 8. 7

Copyright:
Copyright (C) 2014

Original file name:
Wizard.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Language:
Spanish (Spain, International Sort)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/9/2014 8:00:00 PM

Valid to:
10/10/2015 7:59:59 PM

Subject:
CN=Yumon System SL, O=Yumon System SL, L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3AA6674633422C69E81B62EE2A7C074B

File PE Metadata
Compilation timestamp:
12/5/2014 8:45:56 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:jK6fxaOhc2dC3Rfzy41rWibAiCEydknBds0a0m1lK8s:m6JpC3RLy41aibAiCE1Ps0a1LKH

Entry address:
0x17C13B

Entry point:
60, E8, 00, 00, 00, 00, 58, 05, 5A, 0B, 00, 00, 8B, 30, 03, F0, 2B, C0, 8B, FE, 66, AD, C1, E0, 0C, 8B, C8, 50, AD, 2B, C8, 03, F1, 8B, C8, 57, 51, 49, 8A, 44, 39, 06, 88, 04, 31, 75, F6, 2B, C0, AC, 8B, C8, 80, E1, F0, 24, 0F, C1, E1, 0C, 8A, E8, AC, 0B, C8, 51, 02, CD, BD, 00, FD, FF, FF, D3, E5, 59, 58, 8B, DC, 8D, A4, 6C, 90, F1, FF, FF, 51, 2B, C9, 51, 51, 8B, CC, 51, 66, 8B, 17, C1, E2, 0C, 52, 57, 83, C1, 04, 51, 50, 83, C1, 04, 56, 51, E8, 5E, 00, 00, 00, 8B, E3, 5E, 5A, 2B, C0, 89, 04, 32, B4, 10...
 
[+]

Entropy:
7.9042

Packer / compiler:
ASPack v1.08.04

Code size:
144.5 KB (147,968 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security