setup.exe

Flash Video Player

Air Software

Warning, this is not the legitimate setup program for Flash Video Player. The setup is bootstrapped by the Air Installer 'download manager' (a pay-per-install monetization download manager) that bundles unwanted software (adware, toolbars, extensions) during setup while deciving the user into thinking they are downloading the stadard installation setup from Flash Video Player. The application setup.exe by Air Software has been detected as adware by 28 anti-malware scanners. The program is a setup application that uses the AirInstaller Download Manager installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
AirInstaller Inc.  (signed by Air Software)

Product:
Flash Video Player

Version:
2.0.3.2

MD5:
503b4f32ddabf14cca1e4943cc66edd6

SHA-1:
d43a7e319b601e0a5bd15d81b99ffc37c02401d2

SHA-256:
035e7ed0272c39dc667f52c8860e05f5a698b0c8ef1cac4f98effa1bec7337f2

Scanner detections:
28 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/24/2024 4:11:59 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.AirInstaller.4
358

Agnitum Outpost
PUA.AirAd
7.1.1

Avira AntiVirus
ADWARE/Adware.Gen
7.11.183.186

avast!
Win32:Adware-CAH [PUP]
2014.9-160212

Bitdefender
Gen:Variant.Application.Bundler.AirInstaller.4
1.0.20.215

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.AirAdInstaller.A
20024

Dr.Web
Trojan.SMSSend.4925
9.0.1.043

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.AirInstaller
8.16.02.12.12

ESET NOD32
Win32/AirAdInstaller.A potentially unwanted application
10.7.0.302.0

F-Prot
W32/AirInstall.A7.gen
v6.4.6.5.141

F-Secure
Riskware.Gen:Variant.Application.Bundler
11.2016-12-02_6

G Data
Win32.Adware.Airadinstaller
16.2.24

IKARUS anti.virus
PUA.AirAdInstaller
t3scan.1.8.3.0

K7 AntiVirus
Unwanted-Program
13.185.13943

Malwarebytes
PUP.Optional.Bundle
v2016.02.12.12

MicroWorld eScan
Gen:Variant.Application.Bundler.AirInstaller.4
17.0.0.129

NANO AntiVirus
Riskware.Win32.AirAdInstaller.ddzazh
0.28.6.62995

Norman
Gen:Variant.Application.Bundler.AirInstaller.4
11.20160212

Panda Antivirus
Adware/AirInstaller
16.02.12.12

Qihoo 360 Security
Win32/Virus.Adware.d78
1.0.0.1015

Quick Heal
Adware.AirAdInstaller.I5
2.16.14.00

Reason Heuristics
PUP.Air Software.AirSoftware.Bundler (M)
16.2.12.0

Rising Antivirus
PE:PUF.Airinstall!1.9C4C
23.00.65.16210

Sophos
PUA 'AirInstaller'
5.15

Trend Micro House Call
HV_ZYX_BK083DEB.TOMC
7.2.43

Vba32 AntiVirus
AdWare.AirAdInstaller
3.12.26.3

VIPRE Antivirus
Threat.4782985
34232

File size:
935.6 KB (958,104 bytes)

Product version:
2.0.3.2

Copyright:
(c) AirInstaller. All rights reserved.

Original file name:
AirInstallerOne.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
AirInstaller Download Manager

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/29/2012 4:00:00 PM

Valid to:
3/1/2013 3:59:59 PM

Subject:
CN=Air Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Air Software, L=Victoria, S=British Columbia, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
36D5AA8967E82240D5AFEC2F301B54ED

File PE Metadata
Compilation timestamp:
10/11/2012 11:41:03 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:GhkB+2A+vopY/7+fzmQJqC5Hsba8BISDLtty1d:Gqoi805FCxsba8+SVs

Entry address:
0x228C50

Entry point:
60, BE, 00, 40, 54, 00, 8D, BE, 00, D0, EB, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8887

Packer / compiler:
UPX 2.90LZMA

Code size:
916 KB (937,984 bytes)

Remove setup.exe - Powered by Reason Core Security