Air Software

Publisher Information

Air Software is a software publisher located in Victoria, British Columbia in Canada*. The company is a primary distributor of unwanted software. Air Software distributes a download mnanager and installer as well as wraps open source and legitimate software with advertising offers that include adware and toolbars. The company owns dozens of 'download sites' that bundle such unwanted software (Conduit, Ask, Babylon, etc.) with its Air Installer. Thre are 4 additional code signing certificates issued to this publisher.
Remove Air Software Malware - Powered by Reason Core Security
Authority:
COMODO CA Limited

Valid from:
6/26/2011 8:00:00 PM

Valid to:
6/26/2012 7:59:59 PM

Subject:
CN=Air Software, O=Air Software, STREET=185-911 Yates St., STREET="Suite #327", L=Victoria, S=BC, PostalCode=V8V4Y9, C=CA

Issuer:
CN=COMODO Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00c3bfaff5374660a208126e655cbd3e13

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
DownloadManager.Air Software, DownloadManager.Bundler.Air Software, PUP.Air Software.AirSoftware.Bundler (M), PUP.Air Software.AirSoftware (M)
100.00%

Dr.Web
Adware.Downware.163, Adware.Downware.86, Adware.Downware.103, Adware.Downware.90, Adware.Downware.202, Adware.Downware.56
24.00%

Comodo Security
Application.Win32.AirAdInstaller.A
12.00%

Panda Antivirus
Adware/AirInstaller
12.00%

Sophos
AirInstaller (PUA)
10.00%

AVG
Win32/DH{gRKBE0GBDnx9ICVXY2RO}, Win32/DH{gRKBE0GBDnx9ICVXY04}, Win32/DH{gRKBE0EgJYEOfH1XY2RO}, Found Win32/DH{gRKBE0GBDnx9ICVXY2RO}
10.00%

Malwarebytes
PUP.Optional.Bundle
6.00%

ByteHero BDV
Trojan.Malware.Win32.xPack.i
6.00%

IKARUS anti.virus
PUA.AirAdInstaller
4.00%

MicroWorld eScan
Gen:Variant.Application.Bundler.AirInstaller.4
4.00%

1 / 68      (Adware)
air1aa1.tmp.exe (Software Installer by AirInstaller)  (48a763118bfedac6d331ef07a56b045a)

1 / 68      (Adware)
airfec0.tmp.exe (Software Installer by AirInstaller)  (ae937dcb5a53aae68618bd9e457c8e12)

1 / 68      (Adware)
gimp.exe (GIMP)  (d68534d9dbe7998c1b8a9253120d6d06)

1 / 68      (Adware)
abiwordsetup.exe (Abiword_Blue by AirInstaller)  (258d3eb5eac7a5a7f73ae03ab704f3c7)

1 / 68      (Adware)
unins000.exe  (e683e78e83e4a205d0e013fa7fec53a9)

1 / 68      (Adware)
pidgin_setup.exe (Pidgin by AirInstaller)  (3191e1e0776b5e41e13e21b28d896487)

3 / 68      (Adware)
gimp_setup.exe (GIMP by AirInstaller)  (c722a95933b963d201c1414ba82fc50a)

1 / 68      (Adware)
air31f4.tmp.exe (Software Installer by AirInstaller)  (0ff02ffc1bb7085338afd178ea3b2125)

12 / 68    (Adware)
yahoo_pidgin_setup.exe (Yahoo_Pidgin by AirInstaller)  (ced88c9d26056e218a96624f8ddff37c)

1 / 68      (Adware)
install_helper.exe  (6a560bcedfd242e0c998a6634915e24a)

1 / 68      (Adware)
air6176.tmp.exe (Software Installer by AirInstaller)  (055104f540dbc54c79a8a5ebefa062be)

1 / 68      (Adware)
sumatra_pdf_setup.exe (Sumatra_PDF by AirInstaller)  (3323d87ee9729bf8cea1f8803626fed5)

1 / 68      (Adware)

1 / 68      (Adware)
gimp_setup.exe (GIMP by AirInstaller)  (f7149491da5867e31ddc067d10bff0a1)

1 / 68      (Adware)
unins000.exe  (8b59f93b061794de5b874a11d2e80b43)

1 / 68      (Adware)
openoffice_setup.exe (OpenOffice by AirInstaller)  (deed69822de5249ed69530494012b3a7)

1 / 68      (Adware)
openoffice_setup.exe (OpenOffice by AirInstaller)  (fb754b4693a0e6b73ce05097a51ecf3a)

1 / 68      (Adware)
yahoo_pidgin_setup.exe (Yahoo_Pidgin by AirInstaller)  (423d85d63c5441513c0c908fae68116f)

10 / 68    (Adware)
infrarecorder_setup.exe (InfraRecorder by AirInstaller)  (dad35bede90ae7eb8e246c4ec8112ff5)

1 / 68      (Adware)
infrarecorder_setup.exe (InfraRecorder by AirInstaller)  (d673261a400decd576ef7c0de52b729f)

1 / 68      (Adware)
pidgin_setup.exe (Pidgin by AirInstaller)  (71e4f0f54497268f6a1279199d0ce820)

1 / 68      (Adware)
nuancepdfreader.exe (Nuance PDF Reader)  (388b9f31dc49020b7012666123cf00ac)

1 / 68      (Adware)
infrarecorder_setup.exe (InfraRecorder by AirInstaller)  (e6c98d65d60b08791f35b22c0039c50e)

1 / 68      (Adware)
infrarecorder.exe (InfraRecorder)  (2d5cc25c20d373e5221ed0f1c3cc3ffc)

2 / 68      (Adware)

1 / 68      (Adware)
unins000.exe  (b4417753fd614b76d7c66be300f75f6e)

4 / 68      (Adware)
7zip_setup.exe (7-Zip by AirInstaller)  (2517d79cc454a2e9d8496e5154e3e571)

4 / 68      (Adware)
yahoo_pidgin_setup.exe (Yahoo_Pidgin by AirInstaller)  (021c01b8c9fd713ec6ccf135bc59c102)

6 / 68      (Adware)
msn_pidgin_setup.exe (MSN_Pidgin by AirInstaller)  (f5e7d64fdf5aec09f665522a2455270a)

2 / 68      (Adware)
vlcmediaplayer.exe (VLC Media Player)  (703687a1add4922ef38c9a42c6a0c437)

 
Latest 30 of 80 files

Downloads URLs for files signed by Air Software.

1 / 68      (Adware)

3 / 68      (Adware)

Top-level domains owned by Air Software.

The following websites host and distribute files published by Air Software.

The certificates below are also signed by Air Software.

6CF1F27B980B710E832023D598BFDACF  (Mar 08, 2015 to May 07, 2016)

16564ACDBB7F9D84DADD0FD418C69A51  (Feb 16, 2015 to Apr 17, 2016)

3AC786E09219DF82DA830E461D4FC39F  (Jan 24, 2013 to Mar 26, 2015)

36D5AA8967E82240D5AFEC2F301B54ED  (Feb 29, 2012 to Mar 01, 2013)

The following publishers (by Authenticode signature organization name) are related.

Remove Air Software Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Air Software by COMODO CA Limited on June 26, 2011 with the serial number '00c3bfaff5374660a208126e655cbd3e13'.