Microsoft Security Essentials.exe

Microsoft Security Essentials

Download Assistant

This is part of the Air Installer, a download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application Microsoft Security Essentials.exe by Download Assistant has been detected as adware by 23 anti-malware scanners. The program is a setup application that uses the AirInstaller Download Manager installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent.
Publisher:
DownloadAsst_New  (signed by Download Assistant)

Product:
Microsoft Security Essentials

Version:
3.0.0.105

MD5:
28949fca577b3ce5b5ed57716c145311

SHA-1:
6c46569e7973ab48fa2337993ebcf990a694b77c

SHA-256:
a1aa3bcf0054fc4d7e49d3efe5b24aa838bebbb6addca1036279e583e3c70091

Scanner detections:
23 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/24/2024 12:46:47 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.AirInstaller.5
5735023

AhnLab V3 Security
PUP/Win32.Bundler
2015.06.11

Avira AntiVirus
TR/Crypt.XPACK.Gen
7.11.30.172

Arcabit
Trojan.Application.Bundler.AirInstaller.5
1.0.0.425

avast!
Win32:Adware-CKC [PUP]
150602-1

AVG
Generic
2016.0.3082

Bitdefender
Gen:Variant.Application.Bundler.AirInstaller.5
1.0.20.805

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.DownloadAssistant.S
22406

Dr.Web
Trojan.Vittalia.30
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.AirInstaller
10.0.0.5366

ESET NOD32
Win32/DownloadAssistant.A potentially unwanted application
7.0.302.0

F-Secure
Riskware.Gen:Variant.Application.Bundler
5.14.151

G Data
Gen:Variant.Application.Bundler.AirInstaller
15.6.25

K7 AntiVirus
Unwanted-Program
13.204.16199

Malwarebytes
PUP.Optional.BundleInstaller.A
v2015.06.10.01

MicroWorld eScan
Gen:Variant.Application.Bundler.AirInstaller.5
16.0.0.483

NANO AntiVirus
Trojan.Win32.Vittalia.dqfrig
0.30.24.2086

Norman
Gen:Variant.Application.Bundler.AirInstaller.5
02.06.2015 14:23:46

Panda Antivirus
Trj/Genetic.gen
15.06.10.01

Reason Heuristics
PUP.Air Software.Bundler
15.6.10.9

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.15608

VIPRE Antivirus
AirInstaller
41000

File size:
961.7 KB (984,768 bytes)

Product version:
3.0.0.105

Copyright:
(c) DownloadAsst_New

Original file name:
Microsoft Security Essentials.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
AirInstaller Download Manager

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\microsoft security essentials.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/16/2015 12:00:00 AM

Valid to:
2/16/2016 11:59:59 PM

Subject:
CN=Download Assistant, O=Download Assistant, L=Victoria, S=British Columbia, C=CA

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
3784E4CAC60231ED82FD7E8E845E8CE3

File PE Metadata
Compilation timestamp:
6/10/2015 2:13:03 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:FYX9z/4fFVUs+cRy6UlHUnZwEOmCJ903R6PpE+l:swfFV66U2WJ63QPW+l

Entry address:
0x126A

Entry point:
55, 8B, EC, 83, EC, 10, 53, 56, 57, 6A, 00, FF, 15, 08, 10, 49, 00, 8B, F8, 33, D2, 8B, CF, 8B, 5F, 3C, 03, DF, 2B, 05, 1C, 10, 40, 00, 89, 45, F4, 1B, D2, F7, D8, 89, 55, F8, 0F, B7, 73, 14, 83, D2, 00, F7, DA, 89, 75, F0, 52, 8B, 93, A0, 00, 00, 00, 50, 8B, 44, 1E, 24, 03, 05, 28, 10, 40, 00, 50, FF, B3, A4, 00, 00, 00, E8, 88, FD, FF, FF, 8B, 54, 1E, 28, 83, C4, 10, A1, 28, 10, 40, 00, 2B, D0, 83, FA, 01, 76, 0D, 8B, 4C, 1E, 24, 03, C8, 03, CF, E8, F2, FE, FF, FF, A1, 20, 10, 40, 00, 83, C6, 40, 03, F3...
 
[+]

Entropy:
7.0502

Developed / compiled with:
Microsoft Visual C++

Code size:
574.5 KB (588,288 bytes)

The file Microsoft Security Essentials.exe has been seen being distributed by the following URL.

Remove Microsoft Security Essentials.exe - Powered by Reason Core Security