Bootstrapper.exe

IMBooster

Iminent

This is the SIEN AppScion Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application Bootstrapper.exe, “IMinent bootstrapper” by Iminent has been detected as a potentially unwanted program by 7 anti-malware scanners. The program is a setup application that uses the SIEN SuperInstall installer.
Publisher:
Iminent  (signed and verified)

Product:
IMBooster

Description:
IMinent bootstrapper

Version:
4.37.0.0

MD5:
d0781a8c63416a1e0be3dd84641b9e34

SHA-1:
a5fec06c359598d53db481ff09219915fdd5812e

SHA-256:
a4195c03ebd6a4bebf2a50f7ca2235fd08d497efed350c0fd2074544058ea731

Scanner detections:
7 / 68

Status:
Potentially unwanted

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/23/2024 8:19:48 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Trash.Gen
7.11.144.252

AVG
Iminent
2017.0.2835

Dr.Web
Trojan.Damaged.1
9.0.1.044

ESET NOD32
Win32/Toolbar.Iminent.E potentially unwanted application
10.7.0.302.0

Reason Heuristics
PUP.Sien.Iminent.Bundler (M)
16.2.13.0

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
9327

VIPRE Antivirus
Iminent
25152

File size:
804 KB (823,264 bytes)

Product version:
4.37.0.0

Copyright:
(c)Iminent. All rights reserved.

Original file name:
Bootstrapper.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
SIEN SuperInstall

Language:
English (United States)

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/26/2010 7:31:06 PM

Valid to:
1/27/2012 7:31:03 PM

Subject:
CN=Iminent, O=Iminent, L=Paris, S=France, C=FR

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001266AC7D81A

File PE Metadata
Compilation timestamp:
9/22/2011 4:05:47 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:X8XRO/HV5xIOmfEI+ufZkf6L+nJKxMxkVaRzVl2r:X8snmH5gnJKxMxkkRW

Entry address:
0x200310

Entry point:
60, BE, 00, 50, 55, 00, 8D, BE, 00, C0, EA, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8485

Packer / compiler:
UPX 2.90LZMA

Code size:
688 KB (704,512 bytes)

Remove Bootstrapper.exe - Powered by Reason Core Security