setup.exe.exe

SoftZipper

This is not a toolbar

The application setup.exe.exe, “SoftZipper ” by This is not a toolbar has been detected as adware by 26 anti-malware scanners. The program is a setup application that uses the AirInstaller Download Manager installer.
Publisher:
ScottTest   (signed by This is not a toolbar)

Product:
SoftZipper

Description:
SoftZipper

Version:
2.0.4.98

MD5:
30a7e90cbb5b1eb52597e80562644387

SHA-1:
69ef4db76b773ea805a12916e0c9b8d981743cbb

SHA-256:
d5c8fc43d0981f1eb0f8231e875aab2eeb7054c1a3e57066bd990d4c98eb2e48

Scanner detections:
26 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/23/2024 10:22:28 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
AdWare.W32.AirAdInstaller
2.1.4+

Agnitum Outpost
PUA.AirAd
7.1.1

AhnLab V3 Security
PUP/Win32.AirAdInstaller
15.12.11

Avira AntiVirus
ADWARE/Adware.Gen
7.11.137.70

avast!
PUP-gen [PUP]
2014.9-151211

AVG
Adware BundleApp_r.D
2016.0.2899

Clam AntiVirus
Win.Adware.Airadinstaller-54
0.98/19485

Comodo Security
Application.Win32.AirAdInstaller.A
17759

Dr.Web
Trojan.SMSSend.4902
9.0.1.0345

ESET NOD32
Win32/AirAdInstaller.A potentially unwanted application
9.7.0.302.0

F-Prot
W32/AirInstall.A.gen
v6.4.6.5.141

G Data
Win32.Adware.Airadinstaller
15.12.24

IKARUS anti.virus
Win32.Malware
t3scan.2.2.29

K7 AntiVirus
Unwanted-Program
13.176.11663

Kaspersky
not-a-virus:AdWare.Win32.AirAdInstaller
14.0.0.988

Malwarebytes
PUP.Optional.AirInstaller
v2015.12.11.11

NANO AntiVirus
Riskware.Win32.AirAdInstaller.cwbkcs
0.28.0.58873

Panda Antivirus
Trj/Genetic.gen
15.12.11.11

Qihoo 360 Security
HEUR/Malware.QVM01.Gen
1.0.0.1015

Quick Heal
Adware.AirAdInstaller.I5
12.15.14.00

Reason Heuristics
PUP.Air Software.Thisisnotatoolbar.Bundler (M)
15.12.11.11

Rising Antivirus
PE:PUF.Airinstall!1.9C4C
23.00.65.151209

Sophos
AirInstaller
4.97

Vba32 AntiVirus
AdWare.AirAdInstaller.ajov
3.12.24.3

VIPRE Antivirus
Threat.4784938
29418

Zillya! Antivirus
Adware.AirAdInstaller.Win32.248
2.0.0.1945

File size:
838.8 KB (858,912 bytes)

Product version:
2.0.4.98

Copyright:
(c) ScottTest

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
AirInstaller Download Manager

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe.exe

Digital Signature
Authority:
Highly Trusted Software - You Should Install

Valid from:
6/14/2013 11:31:33 AM

Valid to:
12/31/2039 3:59:59 PM

Subject:
CN=This is not a toolbar

Issuer:
CN=Highly Trusted Software - You Should Install

Serial number:
6EB5DEF1106583B14453B25B18179CB2

File PE Metadata
Compilation timestamp:
2/21/2014 10:11:40 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:cGHxeBsps2J3ZjdKC1pjhKXbHezi7KZmTW9T:cGHxeyJJVdKO5oFeZR

Entry address:
0x268290

Entry point:
60, BE, 00, 50, 5A, 00, 8D, BE, 00, C0, E5, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8861

Packer / compiler:
UPX 2.90LZMA

Code size:
784 KB (802,816 bytes)

Remove setup.exe.exe - Powered by Reason Core Security