AirInstaller.exe
Download Manager
Air Software
It uses the Air Installer distribution platform (a pay-per-install monetization download manager) to bundle unwanted software such as adware and browser toolbars during setup. The application AirInstaller.exe by Air Software has been detected as adware by 2 anti-malware scanners. The program is a setup application that uses the AirInstaller Download Manager installer. The file has been seen being downloaded from download.zipdownloader.com.
File name:
AirInstaller.exe
Publisher:
AirInstaller Inc. (signed by Air Software)
MD5:
8b2c61c1fb74f2d0aab0b477c9bc01e2
SHA-1:
bd116cff8f3de72f8cefbc08ce103f7045081525
SHA-256:
5fc63e1f294d1e79ab1a37b6769533ef958e5cc8617f64c2e3f0cb77fd21188b
Scanner detections:
2 / 68
Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.
Analysis date:
11/27/2024 1:36:25 AM UTC (today)
Scan engine
Detection
Engine version
Boost by Reason
Adware.AirSoftware.M
2013.8.2.11
Reason Heuristics
DownloadManager.AirSoftware.M
14.8.7.18
File size:
804.4 KB (823,720 bytes)
Copyright:
(c) AirInstaller. All rights reserved.
Original file name:
AirInstaller.exe
File type:
Executable application (Win32 EXE)
Bundler/Installer:
AirInstaller Download Manager
Language:
English (United States)
Common path:
C:\users\{user}\downloads\airinstaller.exe
Valid from:
1/24/2013 7:00:00 PM
Valid to:
3/26/2015 7:59:59 PM
Subject:
CN=Air Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Air Software, L=Victoria, S=British Columbia, C=CA
Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US
Serial number:
3AC786E09219DF82DA830E461D4FC39F
Compilation timestamp:
7/30/2013 12:39:55 PM
Code size:
768 KB (786,432 bytes)
The file AirInstaller.exe has been seen being distributed by the following URL.