Microsoft.Expression.Interactions.dll

Microsoft.Expression.Interactions

Iminent

This is the SIEN AppScion Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The module Microsoft.Expression.Interactions.dll by Iminent has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the SIEN SuperInstall installer.
Publisher:
Microsoft Corporation  (signed by Iminent)

Product:
Microsoft.Expression.Interactions

Version:
2.0.20525.0

MD5:
2fabe4d27969817c08719d66fb85a706

SHA-1:
3da6e0d87a255dcfd273f99d10ab144c3a7bc7d3

SHA-256:
709141337d1c53ffdf7a7dce489a339f3dd820fa14c0a8a5624c07e6f99942f0

Scanner detections:
2 / 68

Status:
Potentially unwanted

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/16/2024 4:38:12 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien.Iminent.Bundler (M)
16.2.12.3

VIPRE Antivirus
Iminent
23088

File size:
94.6 KB (96,888 bytes)

Product version:
2.0.20525.0

Copyright:
Copyright (c) Microsoft Corporation. All rights reserved.

Original file name:
Microsoft.Expression.Interactions.dll

File type:
Dynamic link library (Win32 DLL)

Bundler/Installer:
SIEN SuperInstall

Language:
Language Neutral

Common path:
C:\Program Files\iminent\microsoft.expression.interactions.dll

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/31/2012 10:55:45 AM

Valid to:
3/2/2014 10:55:45 AM

Subject:
CN=Iminent, O=Iminent, L=Paris, S=France, C=FR

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11214EA925C07E01E1C06B597DD4B36FAA8B

File PE Metadata
Compilation timestamp:
5/26/2010 3:12:05 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:brf5GttgxHXEuRmG5rtkGY4CEmWAxXSSYhhS98ca2Wvsd65FJDlGWwkEyHfx:X5GttWHXEUx5r65LxXshk8JDIWP/x

Entry address:
0x17A1E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
87 KB (89,088 bytes)

Remove Microsoft.Expression.Interactions.dll - Powered by Reason Core Security