setup.exe

Flash Video Player

Air Software

Warning, this is not the legitimate setup program for Flash Video Player. The setup is bootstrapped by the Air Installer 'download manager' (a pay-per-install monetization download manager) that bundles unwanted software (adware, toolbars, extensions) during setup while deciving the user into thinking they are downloading the stadard installation setup from Flash Video Player. The application setup.exe by Air Software has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the AirInstaller Download Manager installer.
Publisher:
AirInstaller Inc.  (signed by Air Software)

Product:
Flash Video Player

Version:
2.0.3.3

MD5:
4774fa08f2e01f5e2934d518f841b75c

SHA-1:
d96393aba2c55dba91a06b2e870477e2f67e23f6

SHA-256:
218b4aeea414e790a922728b22de5525c959268e17037008f3441e224dde7636

Scanner detections:
11 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/14/2024 4:18:05 PM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Application.Win32.AirAdInstaller.A
19281

Dr.Web
Trojan.SMSSend.4803
9.0.1.05190

ESET NOD32
Win32/AirAdInstaller.A potentially unwanted application
7.0.302.0

F-Prot
W32/AirInstall.A7.gen
4.6.5.141

K7 AntiVirus
Unwanted-Program
13.183.13139

Panda Antivirus
Adware/AirInstaller
14.08.22.07

Reason Heuristics
DownloadManager.AirSoftware.F
14.8.22.17

Rising Antivirus
PE:PUF.Airinstall!1.9C4C
23.00.65.14820

Sophos
AirInstaller
4.98

Trend Micro House Call
HV_ZYX_BK0841DD.TOMC
7.2.234

VIPRE Antivirus
Threat.4782985
32210

File size:
935.1 KB (957,592 bytes)

Product version:
2.0.3.3

Copyright:
(c) AirInstaller. All rights reserved.

Original file name:
AirInstallerOne.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
AirInstaller Download Manager

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/29/2012 6:00:00 PM

Valid to:
3/1/2013 5:59:59 PM

Subject:
CN=Air Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Air Software, L=Victoria, S=British Columbia, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
36D5AA8967E82240D5AFEC2F301B54ED

File PE Metadata
Compilation timestamp:
10/13/2012 4:38:49 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:7lwFELv1MhQLH4iXrMYdzSV2VXPS/aR92ib1/MLX3j:7gERMCHDY0SwZKw2ipcj

Entry address:
0x227A80

Entry point:
60, BE, 00, 30, 54, 00, 8D, BE, 00, E0, EB, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8890

Packer / compiler:
UPX 2.90LZMA

Code size:
916 KB (937,984 bytes)

Remove setup.exe - Powered by Reason Core Security