setup.exe

Digital Plugin SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Digital Plugin SL has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer.
Publisher:
Digital Plugin SL  (signed and verified)

MD5:
6e264bf19b3944e599890b2dd4703d24

SHA-1:
e7280d9ade0bf44f3efbd5326efff4742547aff7

SHA-256:
0cd80c2422d33aee41d2503fc82af170cbb225be3d5ecab49a29cb7a6fe6283e

Scanner detections:
11 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/15/2024 9:44:35 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-PUP/SoftPulse
2015.02.28

Avira AntiVirus
PUA/Softpulse.Gen
7.11.212.170

AVG
Generic
2016.0.3186

Clam AntiVirus
Win.Adware.MultiPlug-31138
0.98/20118

ESET NOD32
Win32/SoftPulse.X potentially unwanted (variant)
9.11243

K7 AntiVirus
Unwanted-Program
13.1915108

Kaspersky
not-a-virus:Downloader.Win32.DriverUpd
15.0.0.543

Malwarebytes
PUP.Optional.SoftPulse
v2015.02.27.08

NANO AntiVirus
Trojan.Win32.DriverUpd.dojhbs
0.30.0.296

Reason Heuristics
PUP.Installer.Softpulse
15.2.27.8

VIPRE Antivirus
Threat.4150696
37788

File size:
472.5 KB (483,848 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\gxnopoqr\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/20/2015 10:00:00 PM

Valid to:
1/21/2016 9:59:59 PM

Subject:
CN=Digital Plugin SL, O=Digital Plugin SL, STREET=calle El Pozo 17, L=Guia de Isora, S=Santa Cruz de Tenerife, PostalCode=38680, C=ES

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B0E8D67D76278C69BC291F0124BD4648

File PE Metadata
Compilation timestamp:
2/25/2015 9:28:16 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:aieeclBf8B34xcSRYXZ0wh6SrA7UjMH3J0O/oSFO:7MA54JnwkUjMHZDO

Entry address:
0x18E840

Entry point:
60, BE, 00, 40, 52, 00, 8D, BE, 00, D0, ED, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, A0, C9, 18, 00, 57, 83, C3, 04, 53, 68, 3A, A8, 06, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
432 KB (442,368 bytes)

Remove setup.exe - Powered by Reason Core Security