SoftwareUpdate.exe

Software Updater

Air Software

This is part of the Air Installer, a download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application SoftwareUpdate.exe by Air Software has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the AirInstaller Download Manager installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from download.pcfilehelp.com.
Publisher:
Air Software  (signed and verified)

Product:
Software Updater

Version:
2.0.92.0

MD5:
91cc2f12ac09f2b8939d8e624eea0ab6

SHA-1:
be097c9b3239f912b6ffc7cfc0ed99ab14e17b36

SHA-256:
be0c1e73b3ba5001094699b8399ca7562b0e39a92559d34d1a6735948d3603c0

Scanner detections:
10 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/16/2024 3:45:01 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.153852
6099410

avast!
Win32:Adware-gen [Adw]
141130-1

Clam AntiVirus
Win.Adware.Graftor-547
0.98/19741

Dr.Web
Threat.Undefined
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.153852
9.0.0.4668

ESET NOD32
Win32/AirAdInstaller.A potentially unwanted application
7.0.302.0

Kaspersky
not-a-virus:AdWare.Win32.AirAdInstaller
15.0.0.543

Norman
Gen:Variant.Adware.Graftor.153852
04.12.2014 14:30:06

Reason Heuristics
DownloadManager.Bundler.Air Software
15.4.2.1

VIPRE Antivirus
Threat.4784938
35418

File size:
916.1 KB (938,040 bytes)

Product version:
2.0.92.0

Copyright:
(c) Air Software

Original file name:
SoftwareUpdate.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
AirInstaller Download Manager

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\softwareupdate.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/25/2013 12:00:00 AM

Valid to:
3/26/2015 11:59:59 PM

Subject:
CN=Air Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Air Software, L=Victoria, S=British Columbia, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3AC786E09219DF82DA830E461D4FC39F

File PE Metadata
Compilation timestamp:
11/26/2014 10:29:33 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:3OChBG/5vnjYtU4iyoYanXj6TL5oqQoCzRdY7NfHgS8gR+WfEPG1cST2cAJshGpU:e8GcUOoYK6NV0RdIgw+WfgjoaJskI9

Entry address:
0x2A6760

Entry point:
60, BE, 00, 20, 5D, 00, 8D, BE, 00, F0, E2, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8814

Packer / compiler:
UPX 2.90LZMA

The file SoftwareUpdate.exe has been seen being distributed by the following URL.

Remove SoftwareUpdate.exe - Powered by Reason Core Security