setup.exe

Softpulse S.l.

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Softpulse S.l has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from cpm.profeshon.com.
Publisher:
Softpulse S.l.  (signed and verified)

MD5:
2e20f0b6b94460235794e17e5ae68350

SHA-1:
edd59d16b203a6620115e2d9d6291c4aa295bea2

SHA-256:
9fcfebeb1bf7fbc5411a6162b5f7c414787016e0ec93d7a3c59af1e5d53c41c4

Scanner detections:
19 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/22/2025 5:51:38 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.82398
575

Agnitum Outpost
PUA.Downloader
7.1.1

AhnLab V3 Security
Win-PUP/SoftPulse
2015.03.27

Avira AntiVirus
PUA/SoftPulse.oani
3.6.1.96

avast!
Win32:SoftPulse-ER [PUP]
2014.9-150405

AVG
Potentially harmful program Downloader
2016.0.3148

Bitdefender
Gen:Variant.Strictor.82398
1.0.20.475

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.Domaiq.185
9.0.1.095

Emsisoft Anti-Malware
Gen:Variant.Strictor.82398
8.15.04.05.09

Fortinet FortiGate
Riskware/DriverUpd
4/5/2015

G Data
Gen:Variant.Strictor.82398
15.4.25

Kaspersky
not-a-virus:Downloader.Win32.DriverUpd
14.0.0.2235

NANO AntiVirus
Trojan.Win32.DriverUpd.dpsdgl
0.30.8.659

Reason Heuristics
PUP.Bundler.Softpulse
15.4.5.17

Sophos
SoftPulse
4.98

VIPRE Antivirus
Threat.4150696
39354

Zillya! Antivirus
Downloader.DriverUpd.Win32.204
2.0.0.2128

File size:
548.9 KB (562,040 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/22/2014 5:00:00 PM

Valid to:
7/23/2015 4:59:59 PM

Subject:
CN=Softpulse S.l., O=Softpulse S.l., L=Guia de Isora, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
492522DB26914D38C21A797768B88A13

File PE Metadata
Compilation timestamp:
3/26/2015 6:49:32 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:/l/NiIoYAbvZO7wNJgHO78VN4zN8EMDOVUjW3Xg8oSABBX:/ZjoY4EEyHWqN6KjzbPX

Entry address:
0x1E3F00

Entry point:
60, BE, 00, 60, 56, 00, 8D, BE, 00, B0, E9, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 29, 15, 1E, 00, 57, 83, C3, 04, 53, 68, FA, DE, 07, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Entropy:
7.9452  (probably packed)

Code size:
508 KB (520,192 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security