setup.exe

CCleaner

Air Software

This is part of the Air Installer, a download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Air Software has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the AirInstaller Download Manager installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
AirInstaller Inc.  (signed by Air Software)

Product:
CCleaner

Version:
2.0.3.33

MD5:
3f32353c01e0549d2c914cd0e54993ba

SHA-1:
fbbc3b6e068b511cf68c22a2a849933189df3443

SHA-256:
a62ffda4370a6ad3d71bc59121cf68e9ddb43d0e616f970b917d8483c91db67f

Scanner detections:
19 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 10:44:42 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.AirInstaller.4
5777739

avast!
Win32:Adware-CAH [PUP]
150414-0

Bitdefender
Gen:Variant.Application.Bundler.AirInstaller.4
1.0.20.590

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.AirAdInstaller.B
21926

Dr.Web
Adware.Downware.10718
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.AirInstaller
9.0.0.4799

ESET NOD32
Win32/AirAdInstaller.A potentially unwanted (variant)
9.11545

F-Secure
Riskware.Gen:Variant.Application.Bundler
5.13.68

G Data
Gen:Variant.Application.Bundler.AirInstaller
15.4.25

IKARUS anti.virus
AdWare.AirAdInstaller
t3scan.1.8.9.0

K7 AntiVirus
Unwanted-Program
13.203.15737

MicroWorld eScan
Gen:Variant.Application.Bundler.AirInstaller.4
16.0.0.354

Panda Antivirus
Adware/AirInstaller
15.04.28.04

Quick Heal
Adware.AirAdInstaller.I5
4.15.14.00

Reason Heuristics
DownloadManager.Bundler.Air Software
15.4.28.11

Rising Antivirus
PE:PUF.Airinstall!1.9C4C
23.00.65.15426

Sophos
PUA 'AirInstaller'
5.13

VIPRE Antivirus
Threat.4782985
39676

File size:
2.1 MB (2,207,816 bytes)

Product version:
2.0.3.33

Copyright:
(c) AirInstaller. All rights reserved.

Original file name:
AirInstaller.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
AirInstaller Download Manager

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/29/2012 7:00:00 PM

Valid to:
3/1/2013 6:59:59 PM

Subject:
CN=Air Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Air Software, L=Victoria, S=British Columbia, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
36D5AA8967E82240D5AFEC2F301B54ED

File PE Metadata
Compilation timestamp:
1/24/2013 2:55:39 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:3/ZzlCfYAuLlDh+EbJoKzpjhcgnNuCyIr2r5+hKuk4mwmY1PFpzGvVILAyefRMmD:JlsklDhnFoKz/cinr2r5+QYmwmYrpSvB

Entry address:
0x14C6C7

Entry point:
E8, DA, 93, 00, 00, E9, 89, FE, FF, FF, 3B, 0D, B0, 5D, 5E, 00, 75, 02, F3, C3, E9, 61, 94, 00, 00, 8B, FF, 55, 8B, EC, 8B, 45, 14, 56, 85, C0, 74, 41, 83, 7D, 08, 00, 75, 13, E8, E8, 22, 00, 00, 6A, 16, 5E, 89, 30, E8, CF, 96, 00, 00, 8B, C6, EB, 2A, 83, 7D, 10, 00, 74, E7, 39, 45, 0C, 73, 0E, E8, CA, 22, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, DE, 50, FF, 75, 10, FF, 75, 08, E8, E5, 11, 00, 00, 83, C4, 0C, 33, C0, 5E, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 45, 08, 56, 8B, F1, C6, 46, 0C, 00, 85, C0, 75, 63, E8...
 
[+]

Entropy:
6.4904

Code size:
1.5 MB (1,581,568 bytes)

Remove setup.exe - Powered by Reason Core Security