instant messengerinstaller.exe

Download Manager

This is part of the Air Installer, a download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application instant messengerinstaller.exe by Download Manager has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the AirInstaller Download Manager installer.
Publisher:
Download Manager  (signed and verified)

MD5:
30ea929496c00fa1d0591a26fcfb30c5

SHA-1:
dc2bf626ca41b264e0dcea3ee26bbedc7c0e294f

SHA-256:
eda567863f4bb35a5ef2c10e6a1d1902e77edaed57607f9529b9a23a1a64ff9b

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 3:20:02 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Air Software.DownloadManager.Bundler (M)
16.2.9.18

File size:
509.6 KB (521,856 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
AirInstaller Download Manager

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\instant messengerinstaller.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
5/27/2011 1:00:00 AM

Valid to:
5/27/2012 12:59:59 AM

Subject:
CN=Download Manager, O=Download Manager, STREET=26 York Street, L=London, S=Westminster, PostalCode=W1U 6PZ, C=GB

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
7A29EA7E77DAC7B65FC20ECCCB2D8A3C

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:WjwWKBbjIzMnMyvQzy2FI4krvDY23LsNrMlUUmA/Q7HRypnsjs39:woQzMB4zWjDYgeD+/QL0hJ

Entry address:
0x30600

Entry point:
60, BE, 00, C0, 42, 00, 8D, BE, 00, 50, FD, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Entropy:
7.9954

Packer / compiler:
UPX 2.90LZMA

Code size:
20 KB (20,480 bytes)

Remove instant messengerinstaller.exe - Powered by Reason Core Security