setup.exe

Flash Video Player

Air Software

Warning, this is not the legitimate setup program for Flash Video Player. The setup is bootstrapped by the Air Installer 'download manager' (a pay-per-install monetization download manager) that bundles unwanted software (adware, toolbars, extensions) during setup while deciving the user into thinking they are downloading the stadard installation setup from Flash Video Player. The application setup.exe by Air Software has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the AirInstaller Download Manager installer.
Publisher:
AirInstaller Inc.  (signed by Air Software)

Product:
Flash Video Player

Version:
2.0.3.53

MD5:
dafa51afedf89bfc6241c7e6ca219bb3

SHA-1:
00ac41564cf7241b9f5c672058ecf3ceb3761196

SHA-256:
064ce93bf285fa89f36c7fcc0b9a16d9260a8aee8e566111df4c6ff60edce33a

Scanner detections:
13 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/28/2024 4:55:00 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Adware Generic5.ALHN
2014.0.4007

Dr.Web
Adware.Downware.1011
9.0.1.05190

ESET NOD32
Win32/AirAdInstaller.A potentially unwanted application
7.0.302.0

F-Prot
W32/AirInstall.A.gen
4.6.5.141

IKARUS anti.virus
Trojan-Dropper.Agent
t3scan.1.7.5.0

K7 AntiVirus
Unwanted-Program
13.183.13054

NANO AntiVirus
Trojan.Win32.Downware.cxjkpm
0.28.2.61519

Panda Antivirus
Adware/AirInstaller
14.08.17.06

Reason Heuristics
DownloadManager.AirSoftware.F
14.8.17.16

Rising Antivirus
PE:PUF.Airinstall!1.9C4C
23.00.65.14815

Sophos
AirInstaller
4.98

Vba32 AntiVirus
AdWare.AirAdInstaller
3.12.26.3

VIPRE Antivirus
Threat.4782985
32210

File size:
1 MB (1,095,760 bytes)

Product version:
2.0.3.53

Copyright:
(c) AirInstaller. All rights reserved.

Original file name:
AirInstaller.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
AirInstaller Download Manager

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\low\content.ie5\{random}\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/24/2013 7:00:00 PM

Valid to:
3/26/2015 7:59:59 PM

Subject:
CN=Air Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Air Software, L=Victoria, S=British Columbia, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3AC786E09219DF82DA830E461D4FC39F

File PE Metadata
Compilation timestamp:
3/4/2013 6:35:04 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:yfLHuzBsBX4BF3LEV8dz/WqBEJBFeYns+HAeyfLGfgyMpMd:yfj0wk9L80z/LEJBFeJ+HZEGTl

Entry address:
0x2423F0

Entry point:
60, BE, 00, C0, 53, 00, 8D, BE, 00, 50, EC, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Entropy:
7.7643

Packer / compiler:
UPX 2.90LZMA

Code size:
1 MB (1,077,248 bytes)

Remove setup.exe - Powered by Reason Core Security