Setup.exe

Interactive Install

LiveSoftAction SRL

This is the SIEN AppScion Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application Setup.exe by LiveSoftAction SRL has been detected as adware by 27 anti-malware scanners. The program is a setup application that uses the SIEN SuperInstall installer.
Publisher:
Live Soft Action S.R.L.  (signed by LiveSoftAction SRL)

Product:
Interactive Install

Version:
8.28.1.1

MD5:
fb7b7789cb8ac15fd928d29765e37954

SHA-1:
c463bc65ee57ddfb7b39066b12e3b13b97213034

SHA-256:
cd07fb67c383670cd7e3db11b59411b444be2726899a1f984e97da5ce30634ad

Scanner detections:
27 / 68

Status:
Adware

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/19/2024 7:50:53 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.673290
367

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.Installer
2014.09.13

Avira AntiVirus
APPL/Downloader.Gen
7.11.171.206

avast!
Win32:Dropper-gen [Drp]
2014.9-160202

AVG
Generic
2017.0.2845

Bitdefender
Application.Generic.673290
1.0.20.165

Comodo Security
UnclassifiedMalware
19492

Dr.Web
Adware.Downware.5837
9.0.1.033

ESET NOD32
Win32/GetNow (variant)
10.10605

Fortinet FortiGate
Riskware/LiveSoftAction
2/2/2016

F-Prot
W32/A-a4017d21
v6.4.7.1.166

F-Secure
Application.Generic.673290
11.2016-02-02_3

G Data
Win32.Application.Getnow
16.2.24

IKARUS anti.virus
PUA.Getnow
t3scan.1.7.8.0

K7 AntiVirus
Unwanted-Program
13.184.13741

Malwarebytes
PUP.Optional.LiveSoftAction
v2016.02.02.04

McAfee
LiveSoftAction
5600.6501

MicroWorld eScan
Application.Generic.673290
17.0.0.99

NANO AntiVirus
Trojan.Win32.GetNow.dfnyrl
0.28.2.62841

Panda Antivirus
Trj/Genetic.gen
16.02.02.04

Qihoo 360 Security
Win32/Trojan.Dropper.c9f
1.0.0.1015

Reason Heuristics
PUP.Sien.LiveSoftAction.Bundler (M)
16.2.2.16

Sophos
Generic PUA ID
4.98

Trend Micro House Call
TROJ_GEN.R0CBH06H914
7.2.33

Trend Micro
TROJ_GEN.R0CBC0OG914
10.465.02

VIPRE Antivirus
Appscion
34162

File size:
719.5 KB (736,768 bytes)

Product version:
8.28.1.1

Copyright:
(c) Live Soft Action S.R.L. All rights reserved.

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
SIEN SuperInstall

Common path:
C:\users\{user}\appdata\roaming\getnowupdater\update.3\html_res\setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/18/2014 4:50:37 PM

Valid to:
5/29/2015 5:34:53 PM

Subject:
CN=LiveSoftAction SRL, OU=LiveSoftAction SRL, O=LiveSoftAction SRL, L=Bucharest, S=ROMANIA, C=RO

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121FC42685A77DFEC574BF9851EA55E2ADB

File PE Metadata
Compilation timestamp:
7/7/2014 12:22:35 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:KFejbQAFeZheCDCn5vEQ2d2GEg/Ze1gu3nWk6ny894uSe/6y90ME:1jHFeDhel24F+41g2nWHrb6yvE

Entry address:
0x1A9650

Entry point:
60, BE, 00, E0, 50, 00, 8D, BE, 00, 30, EF, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
624 KB (638,976 bytes)

Remove Setup.exe - Powered by Reason Core Security