presentation suiteinstaller.exe

Download Manager

This is part of the Air Installer, a download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application presentation suiteinstaller.exe by Download Manager has been detected as adware by 2 anti-malware scanners. The program is a setup application that uses the AirInstaller Download Manager installer. The file has been seen being downloaded from www.download-free.com.
Publisher:
Download Manager  (signed and verified)

MD5:
ec6c3aaf4cf5d8fc103450cfa9a8a846

SHA-1:
9785076519dcdc52c235bdf365152123b71a1317

SHA-256:
699cde16ad9863bea69de53bfea9f48f6548e72841932fc8ce7af2e32919b23e

Scanner detections:
2 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 8:31:27 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Air Software.Bundler
15.6.2.12

Trend Micro House Call
TROJ_GEN.R06H1DB
7.2.153

File size:
500.4 KB (512,368 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
AirInstaller Download Manager

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\presentation suiteinstaller.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
5/26/2011 7:00:00 PM

Valid to:
5/26/2012 6:59:59 PM

Subject:
CN=Download Manager, O=Download Manager, STREET=26 York Street, L=London, S=Westminster, PostalCode=W1U 6PZ, C=GB

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
7A29EA7E77DAC7B65FC20ECCCB2D8A3C

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:pjlELLKJuL5ocoPTY7/jBlV/c+lv0wcBSPPHFHHddG:plEL+jxrmV/Z8wccF9dG

Entry address:
0x30600

Entry point:
60, BE, 00, C0, 42, 00, 8D, BE, 00, 50, FD, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Entropy:
7.9955

Packer / compiler:
UPX 2.90LZMA

Code size:
20 KB (20,480 bytes)

The file presentation suiteinstaller.exe has been seen being distributed by the following URL.

Remove presentation suiteinstaller.exe - Powered by Reason Core Security