suscan.exe

Install Manager

This is published and distributed via an Adknowledge's advertising supported (adware) software installer. The application suscan.exe by Install Manager has been detected as adware by 3 anti-malware scanners. This file is typically installed with the program Software Updater version 1.9.5 by Air Software which is a potentially unwanted software program.
Publisher:
Install Manager  (signed and verified)

MD5:
e42f092b4daa42730530c14e27effa61

SHA-1:
9a4babaed1b4f38e2b6ae7a95d5ebc18242e31c9

SHA-256:
1db1aedbcc45724f49a065d1207355d81e0bf220dfad2ef19a6fe629b62b3a18

Scanner detections:
3 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Analysis date:
4/25/2024 2:40:09 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3365

Baidu Antivirus
PUA.Win32.AirAdInstaller
4.0.3.1491

Reason Heuristics
PUP.InstallManager.G
14.9.1.4

File size:
217.2 KB (222,408 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\software updater\suscan.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
8/7/2013 1:00:00 AM

Valid to:
8/11/2015 1:00:00 PM

Subject:
CN=Install Manager, O=Install Manager, L=Victoria, S=British Columbia, C=CA

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
06C0BBB90999729C33560EC18A203261

File PE Metadata
Compilation timestamp:
8/12/2014 6:38:08 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

CTPH (ssdeep):
3072:w0JmaIKLVPx/4idi1Cc3uFi1PGMRNSYp+Cg:w00aI8VPxXditsKOMTSxCg

Entry address:
0x13573

Entry point:
E9, E8, 32, 02, 00, E9, D3, 07, 01, 00, E9, BE, 1C, 02, 00, E9, D9, 62, 01, 00, E9, F4, 8D, 00, 00, E9, 6E, 33, 02, 00, E9, 3A, 86, 00, 00, E9, 75, AC, 01, 00, E9, 00, 3C, 00, 00, E9, 9B, FA, 01, 00, E9, B6, EA, 00, 00, E9, BD, 32, 02, 00, E9, DC, F2, 00, 00, E9, 17, 82, 00, 00, E9, 12, 19, 01, 00, E9, 4D, EE, 00, 00, E9, C2, 4A, 02, 00, E9, C3, C0, 01, 00, E9, BB, 2D, 02, 00, E9, 49, EF, 01, 00, E9, 04, EB, 01, 00, E9, 9F, FC, 01, 00, E9, 92, 2A, 02, 00, E9, 95, 5E, 00, 00, E9, 20, AB, 00, 00, E9, 8B, 4B...
 
[+]

Entropy:
5.1816

Developed / compiled with:
Microsoft Visual C++ 8.0 (Debug)

Code size:
169 KB (173,056 bytes)

The file suscan.exe has been discovered within the following program.

The is part of a download manager software bundle that distributes potentially unwanted software offers. From the privacy policy: " Air Software may provide its users with the opportunity to receive special offers, products and/or services from third parties.
software-updater.com
83% remove it
 
Powered by Should I Remove It?

Remove suscan.exe - Powered by Reason Core Security