It uses the Air Installer distribution platform (a pay-per-install monetization download manager) to bundle unwanted software such as adware and browser toolbars during setup. The application setup.exe by Air Software has been detected as adware by 27 anti-malware scanners. The program is a setup application that uses the AirInstaller Download Manager installer. The file has been seen being downloaded from www.downloadwiz.com.
Publisher:
AirInstaller Inc. (signed by Air Software)
MD5:
4a4375a535dd19fee97cc9720cf747e3
SHA-1:
b7f3b333b9af2d681e2d0b3af7a51509a2b2e94e
SHA-256:
644c6b128b18385d92387cd6a1b19df2885425a92d475ffe715082e599009ae0
Scanner detections:
27 / 68
Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.
Analysis date:
12/25/2024 1:23:30 PM UTC (today)
Scan engine
Detection
Engine version
Agnitum Outpost
PUA.AirAd
7.1.1
AhnLab V3 Security
PUP/Win32.AirAdInstaller
2014.06.09
Avira AntiVirus
Adware/AirInst.1174
7.11.137.146
avast!
PUP-gen [PUP]
2014.9-140728
AVG
Adware Generic_r
2015.0.3400
Boost by Reason
Adware.Installer.AirSoftware.F
2013.8.2.9
Clam AntiVirus
Win.Adware.Airadinstaller-4
0.98/19073
Comodo Security
Application.Win32.AirAdInstaller.A
17948
Dr.Web
Adware.Downware.1138
9.0.1.0209
ESET NOD32
Win32/AirAdInstaller.A potentially unwanted application
8.7.0.302.0
F-Prot
W32/AirInstall.A.gen
v6.4.6.5.141
G Data
Win32.Adware.Airadinstaller
14.7.24
IKARUS anti.virus
AdWare.Airinstall
t3scan.2.2.29
K7 AntiVirus
Adware
13.176.11482
Kaspersky
not-a-virus:AdWare.Win32.AirAdInstaller
14.0.0.3495
Malwarebytes
PUP.Optional.AirInstaller
v2014.07.28.12
NANO AntiVirus
Riskware.Win32.Downware.cwfgel
0.28.0.59608
nProtect
Trojan-Clicker/W32.AirAdInstaller.1116296
14.05.20.01
Panda Antivirus
Adware/AirInstaller
14.07.28.12
Qihoo 360 Security
Malware.QVM01.Gen
1.0.0.1015
Quick Heal
Adware.AirAdInstaller.C5
8.14.14.00
Reason Heuristics
DownloadManager.AirSoftware.F
14.8.7.18
Rising Antivirus
PE:PUF.Airinstall!1.9C4C
23.00.65.14726
Vba32 AntiVirus
AdWare.AirAdInstaller
3.12.26.0
VIPRE Antivirus
Threat.4782985
29418
Zillya! Antivirus
Adware.AirAdInstaller.Win32.98
2.0.0.1791
File size:
1.1 MB (1,117,096 bytes)
Copyright:
(c) AirInstaller. All rights reserved.
Original file name:
AirInstaller.exe
File type:
Executable application (Win32 EXE)
Bundler/Installer:
AirInstaller Download Manager
Language:
English (United States)
Common path:
C:\users\{user}\downloads\setup.exe
Valid from:
1/24/2013 4:00:00 PM
Valid to:
3/26/2015 4:59:59 PM
Subject:
CN=Air Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Air Software, L=Victoria, S=British Columbia, C=CA
Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US
Serial number:
3AC786E09219DF82DA830E461D4FC39F
Compilation timestamp:
7/15/2013 9:25:53 AM
Code size:
1.1 MB (1,101,824 bytes)
The file setup.exe has been seen being distributed by the following URL.