setup.exe

HiDef Media Player

Air Software

Warning, this is not the legitimate setup program for HiDef Media Player. The setup is bootstrapped by the Air Installer 'download manager' (a pay-per-install monetization download manager) that bundles unwanted software (adware, toolbars, extensions) during setup while deciving the user into thinking they are downloading the stadard installation setup from HiDef Media Player. The application setup.exe by Air Software has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the AirInstaller Download Manager installer.
Publisher:
AirInstaller Inc.  (signed by Air Software)

Product:
HiDef Media Player

Version:
1.0.0.9

MD5:
7da11f3d79e8844bf90a36c6c70739da

SHA-1:
89b5d09bf81dad197c6e6b08171432ab7920a759

SHA-256:
b25ed1d422cd4e58382621efe6cd87649d5396d96627f3b5674f75ab9d94f710

Scanner detections:
10 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/25/2024 4:41:29 PM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Application.Win32.AirAdInstaller.A
19310

Dr.Web
Trojan.SMSSend.4758
9.0.1.0251

ESET NOD32
Win32/AirAdInstaller (variant)
8.10312

K7 AntiVirus
Unwanted-Program
13.183.13160

NANO AntiVirus
Trojan.Win32.SMSSend.dacstb
0.28.2.61721

Panda Antivirus
Adware/AirInstaller
14.09.08.01

Reason Heuristics
DownloadManager.AirSoftware.F
14.9.8.13

Rising Antivirus
PE:PUF.Airinstall!1.9C4C
23.00.65.14906

Sophos
AirInstaller
4.98

VIPRE Antivirus
AirInstaller
32536

File size:
790.3 KB (809,288 bytes)

Product version:
1.0.0.9

Copyright:
(c) AirInstaller. All rights reserved.

Original file name:
AirInstallerOne.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
AirInstaller Download Manager

Language:
English (United States)

Common path:
C:\users\{user}\downloads\programs\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/29/2012 6:00:00 PM

Valid to:
3/1/2013 5:59:59 PM

Subject:
CN=Air Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Air Software, L=Victoria, S=British Columbia, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
36D5AA8967E82240D5AFEC2F301B54ED

File PE Metadata
Compilation timestamp:
4/26/2012 11:26:54 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:5Z+w8qS2EZlOIAhSc3ihGDuf08RItht/M4KBWjR04jDfT5:5ZkZlpupJt/Mwzd

Entry address:
0x233CD0

Entry point:
60, BE, 00, 30, 57, 00, 8D, BE, 00, E0, E8, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.9121

Packer / compiler:
UPX 2.90LZMA

Code size:
772 KB (790,528 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security