setupshuffledinno.exe

Live Build Default

Download Assistant

This is part of the Air Installer, a download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setupshuffledinno.exe by Download Assistant has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the AirInstaller Download Manager installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from cdn2.chironexfleckerisilver.com.
Publisher:
Download Assistant  (signed and verified)

Product:
Live Build Default

Version:
3.0.0.89

MD5:
2a5e4dc63e2ac81c5f6a0032ebb08f4c

SHA-1:
7470d3f326476fa5142d87aefc0c929841611153

SHA-256:
75a30aba826677a3ebee1a6baae00ec2bc117f3ad9874a8336e31059c51704b1

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/26/2024 5:25:40 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.InstallCore
2015.05.09

avast!
Adware-CKC [PUP]
150423-1

AVG
Potentially harmful program Downloader.EQH
2014.0.4311

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.Vittalia.30
9.0.1.05190

ESET NOD32
Win32/DownloadAssistant.A potentially unwanted application
7.0.302.0

NANO AntiVirus
Trojan.Win32.Vittalia.dqfrig
0.30.24.1357

Reason Heuristics
Threat.Air Software.Bundler
15.5.8.16

Rising Antivirus
PE:Trojan.Win32.SpeedingUpMyPC.a!1075357520
23.00.65.15506

Vba32 AntiVirus
suspected of Malware-Cryptor.FSP.gen
3.12.26.3

VIPRE Antivirus
Threat.4782985
39676

File size:
1 MB (1,100,024 bytes)

Product version:
3.0.0.89

Copyright:
(c) Download Assistant

File type:
Executable application (Win32 EXE)

Bundler/Installer:
AirInstaller Download Manager

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setupshuffledinno.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/15/2015 4:00:00 PM

Valid to:
2/16/2016 3:59:59 PM

Subject:
CN=Download Assistant, O=Download Assistant, L=Victoria, S=British Columbia, C=CA

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
3784E4CAC60231ED82FD7E8E845E8CE3

File PE Metadata
Compilation timestamp:
1/30/2013 6:21:56 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:cxG9A/a+1fiIFW8JHzbudBjN/q6r//7jD:heDHWl9/7

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
6.9387

Developed / compiled with:
Microsoft Visual C++

Code size:
65.5 KB (67,038 bytes)

The file setupshuffledinno.exe has been seen being distributed by the following URL.

Remove setupshuffledinno.exe - Powered by Reason Core Security