avastsetup.exe

Avast Free Antivirus

Download Manager

This is part of the Air Installer, a download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application avastsetup.exe, “Avast Free Antivirus ” by Download Manager has been detected as adware by 26 anti-malware scanners. The program is a setup application that uses the AirInstaller Download Manager installer. With this installer, users are expecting to download the free AVAST Antivirus but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
DownloadManagercerts   (signed by Download Manager)

Product:
Avast Free Antivirus

Description:
Avast Free Antivirus

Version:
2.0.75.0

MD5:
c0b60e31f939b998705fa7622a53a278

SHA-1:
a80a25db20d75301b38eaf7a9ace71ce381fe862

SHA-256:
c3f9dde1f9b0963e14fe61cada20a394cc12c93114d0f1c6ee2fcb3cebe51568

Scanner detections:
26 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
1/12/2025 4:59:33 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.163396
6465013

Agnitum Outpost
PUA.AirAd
7.1.1

AhnLab V3 Security
PUP/Win32.Installer
2015.02.08

Avira AntiVirus
ADWARE/Adware.Gen
7.11.208.112

AVG
Generic
2016.0.3206

Bitdefender
Gen:Variant.Adware.Graftor.163396
1.0.20.190

Clam AntiVirus
Win.Adware.Airadinstaller-299
0.98/20039

Dr.Web
Trojan.SMSSend.5438
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.163396
9.0.0.4799

ESET NOD32
Win32/AirAdInstaller.A potentially unwanted application
7.0.302.0

F-Prot
W32/A-20d9d40c
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Graftor.163396
5.13.68

G Data
Gen:Variant.Adware.Graftor.163396
15.2.25

IKARUS anti.virus
PUA.AirAdInstaller
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.193.14895

Kaspersky
not-a-virus:AdWare.Win32.AirAdInstaller
15.0.0.543

Malwarebytes
PUP.Optional.AirInstaller
v2015.02.07.10

MicroWorld eScan
Gen:Variant.Adware.Graftor.163396
16.0.0.114

NANO AntiVirus
Trojan.Win32.SMSSend.dfhcnr
0.30.0.65070

Norman
Gen:Variant.Adware.Graftor.163396
03.12.2014 13:20:04

Quick Heal
Adware.AirAdInstaller.I5
2.15.14.00

Reason Heuristics
PUP.Installer.Air Software
15.2.7.10

Rising Antivirus
PE:PUF.Airinstall!1.9C4C
23.00.65.15205

Vba32 AntiVirus
AdWare.AirAdInstaller
3.12.26.3

VIPRE Antivirus
Threat.4784938
36694

Zillya! Antivirus
Adware.AirAdInstaller.Win32.607
2.0.0.2056

File size:
910.9 KB (932,712 bytes)

Product version:
2.0.75.0

Copyright:
(c) DownloadManagercerts

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
AirInstaller Download Manager

Language:
English (United States)

Common path:
C:\users\{user}\downloads\avastsetup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/9/2014 7:00:00 PM

Valid to:
7/11/2017 6:59:59 PM

Subject:
CN=Download Manager, O=Download Manager, L=Victoria, S=British Columbia, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6771A39C2739AF7082C1C8D8234BB168

File PE Metadata
Compilation timestamp:
9/10/2014 1:32:39 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:Hf8+jbHxICTU4QK3szWvvf58qpmwSx63fdZxu1G:HRPyCoUdv5RD9u4

Entry address:
0x2A07E0

Entry point:
60, BE, 00, E0, 5C, 00, 8D, BE, 00, 30, E3, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8754

Packer / compiler:
UPX 2.90LZMA

Code size:
844 KB (864,256 bytes)

The file avastsetup.exe has been seen being distributed by the following URL.

Remove avastsetup.exe - Powered by Reason Core Security