gonvisor__2_42.exe

Zeta Installer

LiveSoftAction SRL

This is the SIEN AppScion Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application gonvisor__2_42.exe by LiveSoftAction SRL has been detected as adware by 24 anti-malware scanners. The program is a setup application that uses the SIEN SuperInstall installer. The file has been seen being downloaded from www.gonvisor.com.
Publisher:
LiveSoft Action  (signed by LiveSoftAction SRL)

Product:
Zeta Installer

Version:
9.20.1.2

MD5:
e56cefeeeb5fa8bb50f943f6ab60dcda

SHA-1:
0185fabdeb88239dfcc1ab5d0431d340cbb3e496

SHA-256:
9d3d164c9130894d9c897210243d09c4c00a1bc13b75f77f2d0565d80a3a58a8

Scanner detections:
24 / 68

Status:
Adware

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/25/2024 7:01:50 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Jaiko.615
612

AhnLab V3 Security
PUP/Win32.Agent
2015.06.01

AVG
GetNow
2016.0.3090

Baidu Antivirus
PUA.Win32.GetNow
4.0.3.1562

Bitdefender
Gen:Variant.Adware.Jaiko.615
1.0.20.765

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.GetNow.DI
22301

Dr.Web
Adware.Iminent.25
9.0.1.0153

Emsisoft Anti-Malware
Gen:Variant.Adware.Jaiko.615
8.15.06.02.05

ESET NOD32
Win32/GetNow.I potentially unwanted (variant)
9.11714

Fortinet FortiGate
W32/GetNow.I
6/2/2015

F-Secure
Gen:Variant.Adware.Jaiko
11.2015-02-06_3

G Data
Gen:Variant.Adware.Jaiko.615
15.6.25

IKARUS anti.virus
PUA.Getnow
t3scan.1.9.2.0

K7 AntiVirus
Adware
13.204.16090

McAfee
Artemis!E56CEFEEEB5F
5600.6746

MicroWorld eScan
Gen:Variant.Adware.Jaiko.615
16.0.0.459

Panda Antivirus
PUP/Multitoolbar
15.06.02.05

Qihoo 360 Security
HEUR/QVM11.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Sien.Bundler
15.6.2.17

Sophos
Live Soft Action
4.98

Trend Micro House Call
TROJ_GEN.R00GH09EH15
7.2.153

VIPRE Antivirus
LiveSoftAction
40738

Zillya! Antivirus
Trojan.Black.Win32.34256
2.0.0.2200

File size:
1.1 MB (1,184,752 bytes)

Product version:
9.20.1.2

Copyright:
(c) Live Soft Action. All rights reserved.

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
SIEN SuperInstall

Language:
English (United States)

Common path:
C:\users\{user}\downloads\gonvisor__2_42.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/3/2015 9:24:08 AM

Valid to:
3/3/2016 9:24:08 AM

Subject:
CN=LiveSoftAction SRL, O=LiveSoftAction SRL, L=Bucuresti, C=RO

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112115C730891244FB88071FE814148E0E53

File PE Metadata
Compilation timestamp:
5/11/2015 6:33:58 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:zxB2qCTndgd24uu/wQmZptexrV2JAxNzpxgobHijZ8vLKxyeJyiO:zT2qCed24uomZbexcaxvxgozijsLK38

Entry address:
0x2DFCE0

Entry point:
60, BE, 00, 70, 5D, 00, 8D, BE, 00, A0, E2, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
1 MB (1,085,440 bytes)

The file gonvisor__2_42.exe has been seen being distributed by the following URL.

Remove gonvisor__2_42.exe - Powered by Reason Core Security