Setup.exe

Smart Secure software SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file Setup.exe by Smart Secure software SL has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
Smart Secure software SL  (signed and verified)

MD5:
89df6b3c9df622db7fbad5326cd44c4a

SHA-1:
d9c72f4150f4dd4e2ec02764f9c3e1446f6edd2f

SHA-256:
88825afff7da3804113e4537784c00c8eb03896fbb9daf3e425b85fe14a9aa4e

Scanner detections:
7 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/15/2024 10:59:29 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.SoftPulse
2015.03.26

Avira AntiVirus
PUA/Softpulse.Gen4
3.6.1.96

avast!
Win32:SoftPulse-GP [PUP]
2014.9-150325

Dr.Web
Trojan.Domaiq.175
9.0.1.084

ESET NOD32
Win32/SoftPulse.X potentially unwanted (variant)
9.11376

Reason Heuristics
PUP.Bundler.Softpulse
15.3.25.13

File size:
1.2 MB (1,246,824 bytes)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/22/2015 6:00:00 PM

Valid to:
2/23/2016 5:59:59 PM

Subject:
CN=Smart Secure software SL, O=Smart Secure software SL, STREET="El Pozo, 17", L=Adeje, S=Santa Cruz de Tenerife, PostalCode=38680, C=ES

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
695DAE5AB4D326DD6518FA7C7ABFDADA

File PE Metadata
Compilation timestamp:
3/9/2015 11:22:43 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:RH/49UZ2FNLKC8CjR+ZOkq92j2naAJsqTYi4UHok85q:VAUZeIJt2RdZ4+IQ

Entry address:
0x4D745C

Entry point:
60, E8, 00, 00, 00, 00, 58, 05, 5A, 0B, 00, 00, 8B, 30, 03, F0, 2B, C0, 8B, FE, 66, AD, C1, E0, 0C, 8B, C8, 50, AD, 2B, C8, 03, F1, 8B, C8, 57, 51, 49, 8A, 44, 39, 06, 88, 04, 31, 75, F6, 2B, C0, AC, 8B, C8, 80, E1, F0, 24, 0F, C1, E1, 0C, 8A, E8, AC, 0B, C8, 51, 02, CD, BD, 00, FD, FF, FF, D3, E5, 59, 58, 8B, DC, 8D, A4, 6C, 90, F1, FF, FF, 51, 2B, C9, 51, 51, 8B, CC, 51, 66, 8B, 17, C1, E2, 0C, 52, 57, 83, C1, 04, 51, 50, 83, C1, 04, 56, 51, E8, 5E, 00, 00, 00, 8B, E3, 5E, 5A, 2B, C0, 89, 04, 32, B4, 10...
 
[+]

Entropy:
7.9755

Packer / compiler:
ASPack v1.08.04

Code size:
3.7 MB (3,856,896 bytes)

Remove Setup.exe - Powered by Reason Core Security