AirInstaller.exe
Download Manager
Air Software
It uses the Air Installer distribution platform (a pay-per-install monetization download manager) to bundle unwanted software such as adware and browser toolbars during setup. The application AirInstaller.exe by Air Software has been detected as adware by 2 anti-malware scanners. The program is a setup application that uses the AirInstaller Download Manager installer. The file has been seen being downloaded from zipdownloader.com.
File name:
AirInstaller.exe
Publisher:
AirInstaller Inc. (signed by Air Software)
MD5:
3855b78208e5e8f93dc5375cc078de61
SHA-1:
703d5e09086efb5971f5587929c8f1181125d3e8
SHA-256:
6a2361ec304647a57d9d89a1d0160547a34d662705dd1698835db7b2a9c710f1
Scanner detections:
2 / 68
Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.
Analysis date:
12/25/2024 12:53:37 AM UTC (today)
Scan engine
Detection
Engine version
Boost by Reason
Adware.AirSoftware.M
2013.8.2.11
Reason Heuristics
DownloadManager.AirSoftware.M
14.8.7.18
File size:
804.4 KB (823,720 bytes)
Copyright:
(c) AirInstaller. All rights reserved.
Original file name:
AirInstaller.exe
File type:
Executable application (Win32 EXE)
Bundler/Installer:
AirInstaller Download Manager
Language:
English (United States)
Common path:
C:\users\{user}\downloads\airinstaller.exe
Valid from:
1/24/2013 7:00:00 PM
Valid to:
3/26/2015 7:59:59 PM
Subject:
CN=Air Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Air Software, L=Victoria, S=British Columbia, C=CA
Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US
Serial number:
3AC786E09219DF82DA830E461D4FC39F
Compilation timestamp:
7/30/2013 12:39:55 PM
Code size:
768 KB (786,432 bytes)
The file AirInstaller.exe has been seen being distributed by the following URL.