LiveSoftAction

Publisher Information

LiveSoftAction is a software publisher located in Bucharest, Romania*. The company is a primary distributor of unwanted software. The LiveSoftAction download manager (via getnow.com and part of the SienAppNetwork, AppScion) bundles legitimate and open-source software with the Appscion Download and Install manager. This download manager from SIEN SA bundles all sorts of adware toolbars including utilities such as the company's Iminent toolbar. - "During the download process we show commercial offers such as Iminent, MyCuteBuddy, Beamrise, WeCare, PlayBryte, FreeRideGames, 2YourFace, Wajam, Babylon, Baidu, and others. If a sponsored software offer, like for example a toolbar, will be offered, it shall change the User's home page, default search settings and 404-error traffic, in the event the User selects such options." Thre are 3 additional code signing certificates issued to this publisher.
Remove LiveSoftAction Malware - Powered by Reason Core Security
Authority:
COMODO CA Limited

Valid from:
12/13/2013 1:00:00 AM

Valid to:
12/14/2014 12:59:59 AM

Subject:
CN=LiveSoftAction, O=LiveSoftAction, STREET="Str. Dionisie Lupu, Nr. 64-66, Et.", L=Bucharest, S=Bucharest, PostalCode=010458, C=RO

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2cafd284c3b4147ad3e7601989fccf42

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Sien.LiveSoftAction.Bundler (M)
100.00%

ESET NOD32
Win32/GetNow.E potentially unwanted application, Win32/GetNow.D potentially unwanted application
48.00%

Malwarebytes
PUP.Optional.LiveSoftAction
48.00%

K7 AntiVirus
Unwanted-Program
48.00%

McAfee Web Gateway
BehavesLike.Win32.LiveSoftAction.jc
48.00%

Avira AntiVirus
APPL/Downloader.Gen4
48.00%

Antiy Labs AVL
Trojan/Win32.TSGeneric
48.00%

AVG
Generic, Win.Threat.Medium, Potentially harmful program Downloader
48.00%

Panda Antivirus
Trj/Genetic.gen, Generic Suspicious
48.00%

Baidu Antivirus
PUA.Win32.GetNow
48.00%

34 / 68    (Adware)
Setup.exe (SuperInstall by Live Soft Action S.R.L)  (a7d644376406dc425de2efa2e9508781)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

27 / 68    (Adware)
setup_1.exe (SuperInstall by Live Soft Action S.R.L)  (8ff95bcfcd27d8080350c2d892024081)

22 / 68    (Adware)
setup_0.exe (SuperInstall by Live Soft Action S.R.L)  (6adb2220a9bb0e2ec0b3cdbc00fd8779)

34 / 68    (Adware)
Setup.exe (SuperInstall by Live Soft Action S.R.L)  (c0214c77810ce5c7474d123b3f461799)

27 / 68    (Adware)
setup_un.exe (SuperInstall by Live Soft Action S.R.L)  (504d854198c353dc59a9c09a54b15da5)

34 / 68    (Adware)
Setup.exe (SuperInstall by Live Soft Action S.R.L)  (deda6763fbe4fef842f880d37bba9f0c)

27 / 68    (Adware)
setup_1.exe (SuperInstall by Live Soft Action S.R.L)  (325937abf0e87bb030627913b2bdab73)

22 / 68    (Adware)
setup_0.exe (SuperInstall by Live Soft Action S.R.L)  (850fe8e9761b9fd03f1ee9bdfe9dfaba)

34 / 68    (Adware)
Setup.exe (SuperInstall by Live Soft Action S.R.L)  (c05dde8eedc0e6b961e6cf8f42597c6a)

1 / 68      (Adware)

27 / 68    (Adware)
setup_un.exe (SuperInstall by Live Soft Action S.R.L)  (b869afa773f6277d9d434b517c7de11c)

1 / 68      (Adware)
ioqwklto.exe (SuperInstall by Live Soft Action S.R.L)  (cf668249eeaf7bd2a7c33161d2086edf)

 
Latest 30 of 739 files

Downloads URLs for files signed by LiveSoftAction.

1 / 68      (Adware)
http://stapi.maxrevinstaller.com/api/.../setup.exe  (b6b3e4bb0870fcd478daacbff6f4c20b)

1 / 68      (Adware)
http://stapi.maxrevinstaller.com/api/.../setup.exe  (ff7cd4e836885d29f7b9d30cfabe83c6)

1 / 68      (Adware)
http://stapi.maxrevinstaller.com/api/.../setup.exe  (cb9746c7e940aff8483c5580d4ed1f7e)

1 / 68      (Adware)
http://stapi.maxrevinstaller.com/api/.../setup.exe  (40b1a00c2e82d4da1f327dbe2f692fc4)

27 / 68    (Adware)
http://stapi.maxrevinstaller.com/api/.../setup.exe  (dbe2a9e08fec36c3b70d54b27e15ad17)

The certificates below are also signed by LiveSoftAction.

112170A29B7B1C44372416B604F9BB1609CC  (Apr 13, 2015 to Apr 13, 2016)

0DB89F49425D87D205160442DA55CE38  (Dec 08, 2014 to Dec 09, 2015)

17E4CA22DB0D2CFD73BAACB9BD605BF7  (Jun 04, 2012 to Jun 05, 2014)

The following publishers (by Authenticode signature organization name) are related.

Remove LiveSoftAction Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to LiveSoftAction by COMODO CA Limited on December 13, 2013 with the serial number '2cafd284c3b4147ad3e7601989fccf42'.