Microsoft.Expression.Interactions.dll

Microsoft.Expression.Interactions

Iminent

This is the SIEN AppScion Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The module Microsoft.Expression.Interactions.dll by Iminent has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the SIEN SuperInstall installer.
Publisher:
Microsoft Corporation  (signed by Iminent)

Product:
Microsoft.Expression.Interactions

Version:
2.0.20525.0

MD5:
4998da63e90da0781535c488a221de96

SHA-1:
31d0be73028fbc5a0383c6da4f7cd75b56db50e2

SHA-256:
d9f321cd42eceab64e71cba19b8edb3c5928c2691be6131c900dc18f0886f182

Scanner detections:
2 / 68

Status:
Potentially unwanted

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/23/2024 6:44:26 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien.Iminent.Bundler (M)
16.2.5.14

VIPRE Antivirus
Iminent
23088

File size:
94.6 KB (96,888 bytes)

Product version:
2.0.20525.0

Copyright:
Copyright (c) Microsoft Corporation. All rights reserved.

Original file name:
Microsoft.Expression.Interactions.dll

File type:
Dynamic link library (Win32 DLL)

Bundler/Installer:
SIEN SuperInstall

Common path:
C:\Program Files\iminent\microsoft.expression.interactions.dll

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/31/2012 12:55:45 PM

Valid to:
3/2/2014 12:55:45 PM

Subject:
CN=Iminent, O=Iminent, L=Paris, S=France, C=FR

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11214EA925C07E01E1C06B597DD4B36FAA8B

File PE Metadata
Compilation timestamp:
5/26/2010 4:12:05 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:Jrf5GttgxHXEuRmG5rtkGY4CEmWAxXSSYhhS98ca2Wvsd65FJDlGWwkEyHfg:p5GttWHXEUx5r65LxXshk8JDIWP/g

Entry address:
0x17A1E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
87 KB (89,088 bytes)

Remove Microsoft.Expression.Interactions.dll - Powered by Reason Core Security