Software Update.exe

Software Updater

Installer Setup

This is part of the Air Installer, a download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application Software Update.exe by Installer Setup has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the AirInstaller Download Manager installer. The file has been seen being downloaded from download.myinternetserecurity.com.
Publisher:
Installer Setup  (signed and verified)

Product:
Software Updater

Version:
2.5.0.17

MD5:
d24b193823a4216db1dc132bdbc46be7

SHA-1:
f70caaf92f795601fb105950a6effaf817e04538

SHA-256:
d7a45293232962dfbb792359814a82cd68783df613d58dde51587f944c9a0580

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
1/7/2025 6:55:34 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Air Software.Installe (M)
16.6.16.16

File size:
1 MB (1,063,648 bytes)

Product version:
2.5.0.17

Copyright:
(c) Installer Setup

Original file name:
Software Update.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
AirInstaller Download Manager

Language:
English (United States)

Common path:
C:\users\{user}\downloads\software update.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/24/2014 1:00:00 AM

Valid to:
10/24/2016 12:59:59 AM

Subject:
CN=Installer Setup, O=Installer Setup, L=Vancouver, S=British Columbia, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
114A4CD0F4776DC50DF11F7D51696678

File PE Metadata
Compilation timestamp:
12/8/2014 7:04:46 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:VoD6+8TDnrK9EHpGYDWtGO0HPUbYiFMN/EGlN0iilTgExqwn:VZ+E4EH3DWIO0vjb2sCLdgExb

Entry address:
0x3448E0

Entry point:
60, BE, 00, A0, 64, 00, 8D, BE, 00, 70, DB, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8905

Packer / compiler:
UPX 2.90LZMA

The file Software Update.exe has been seen being distributed by the following URL.

Remove Software Update.exe - Powered by Reason Core Security