linksys wrt54g user guide provided through pdfretriever.com.exe

Interactive Install

LiveSoftAction

The program utilizes the Appscion Download and Install manager, an adware distribution bundler from SIEN SA. The setup program includes ad-supported toolbars and utilities. The application linksys wrt54g user guide provided through pdfretriever.com.exe by LiveSoftAction has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the SIEN SuperInstall installer.
Publisher:
Live Soft Action S.R.L.  (signed by LiveSoftAction)

Product:
Interactive Install

Version:
1.0.11.0

MD5:
b03d3275eef8d4590554120857ca11cf

SHA-1:
6c1496e8d378b118bd5d9daa9c9770db185e3cc0

SHA-256:
145d41820d48979e3ccac479d3836c3aa0d2cbc436ab9d3e5a468ee516c45f3b

Scanner detections:
16 / 68

Status:
Adware

Explanation:
This is a modified installer that uses the Appscion to bundle adware.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/26/2024 10:54:22 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
Adware/Downware.M.4
7.11.152.34

avast!
PUP-gen [PUP]
141119-1

Comodo Security
Application.Win32.GetNow.D
18375

Dr.Web
Adware.Downware.3600
9.0.1.05190

ESET NOD32
Win32/GetNow.B potentially unwanted application
7.0.302.0

F-Prot
W32/A-a4017d21
v6.4.7.1.166

G Data
Win32.Application.Getnow
14.11.24

IKARUS anti.virus
AdWare.Downware
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.183.13611

Malwarebytes
PUP.Optional.LiveSoftAction
v2014.11.28.04

McAfee
LiveSoftAction
5600.6933

NANO AntiVirus
Riskware.Win32.Downware.dcceei
0.28.0.60698

Reason Heuristics
PUP.Installer.LiveSoftAction.GG
14.11.28.3

Sophos
Live Soft Action
4.98

VIPRE Antivirus
Threat.4794174
29732

File size:
691.2 KB (707,768 bytes)

Product version:
1.0.11.0

Copyright:
(c) Live Soft Action S.R.L. All rights reserved.

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
SIEN SuperInstall

Language:
English (United States)

Common path:
C:\users\{user}\downloads\linksys wrt54g user guide provided through pdfretriever.com.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/5/2012 2:00:00 AM

Valid to:
6/6/2014 1:59:59 AM

Subject:
CN=LiveSoftAction, OU=SienAppNetwork, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=LiveSoftAction, L=Bucharest, S=functiune, C=RO

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
17E4CA22DB0D2CFD73BAACB9BD605BF7

File PE Metadata
Compilation timestamp:
5/6/2014 5:00:33 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:L+wcFVeJnv/jKrJ91xZkNsvxJrPkhlLNzUTGMUfxIaJXKy90pj:Cwc/eJnv2rr1xONQxl6lLNAT0f96yqj

Entry address:
0x1981F0

Entry point:
60, BE, 00, 40, 50, 00, 8D, BE, 00, D0, EF, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
596 KB (610,304 bytes)