nuance omnipage 15 user guide provided through pdfretriever.com.exe

Download Manager

LiveSoftAction

The program utilizes the Appscion Download and Install manager, an adware distribution bundler from SIEN SA. The setup program includes ad-supported toolbars and utilities. The application nuance omnipage 15 user guide provided through pdfretriever.com.exe by LiveSoftAction has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the Sien AppScion Download Manager installer.
Publisher:
LiveSoftAction  (signed and verified)

Product:
Download Manager

Version:
1.0.11.0

MD5:
1417330a6385a738f4a8c213f1ce310e

SHA-1:
b8d91603565b599901144757277eadbf0fd2d5db

SHA-256:
ef9d8afc7a2d407af3380af814bb30a5a80248045e0a6055776c1651d6c34b59

Scanner detections:
19 / 68

Status:
Adware

Explanation:
This is a modified installer that uses the Appscion to bundle adware.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 7:54:46 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.142.170

avast!
Malware-gen
2014.9-141022

AVG
Adware BundleApp_r.A
2014.0.4040

Comodo Security
Application.Win32.GetNow.C
18084

Dr.Web
Adware.Downware.2144
9.0.1.05190

ESET NOD32
Win32/GetNow.B potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/GetNow
10/22/2014

F-Prot
W32/A-1932c6fe
v6.4.7.1.166

IKARUS anti.virus
AdWare.Downloader
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.176.11721

Malwarebytes
PUP.Optional.LiveSoftAction.A
v2014.10.22.06

McAfee
LiveSoftAction!E3851D120DB2
5600.6970

NANO AntiVirus
Riskware.Win32.Downware.cwalwi
0.28.0.59048

Reason Heuristics
DownloadManager.LiveSoftAction.
14.10.22.6

Sophos
Live Soft Action
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10284

Trend Micro House Call
TROJ_GEN.F47V0325
7.2.295

VIPRE Antivirus
Appscion
28194

File size:
676.6 KB (692,848 bytes)

Product version:
1.0.11.0

Copyright:
(c) LiveSoftAction. All rights reserved.

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Sien AppScion Download Manager

Language:
English (United States)

Common path:
C:\users\{user}\downloads\nuance omnipage 15 user guide provided through pdfretriever.com.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/5/2012 2:00:00 AM

Valid to:
6/6/2014 1:59:59 AM

Subject:
CN=LiveSoftAction, OU=SienAppNetwork, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=LiveSoftAction, L=Bucharest, S=functiune, C=RO

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
17E4CA22DB0D2CFD73BAACB9BD605BF7

File PE Metadata
Compilation timestamp:
2/7/2014 3:03:56 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:qahUOV7c8TazefLtNUH56qcK/k+0sV8YBytOqDxy9087:qXOVw8TzLt1DvsKXtlDxyL7

Entry address:
0x18D860

Entry point:
60, BE, 00, D0, 4F, 00, 8D, BE, 00, 40, F0, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8970

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
580 KB (593,920 bytes)