System.Windows.Interactivity.dll

System.Windows.Interactivity

Iminent

This is the SIEN AppScion Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The module System.Windows.Interactivity.dll by Iminent has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the SIEN SuperInstall installer.
Publisher:
Microsoft Corporation  (signed by Iminent)

Product:
System.Windows.Interactivity

Version:
1.0.1343.0

MD5:
555f1d1fa45a4448b3dd60ec1739caab

SHA-1:
7df3b32f5969a7a8d4af38a83d0358d5c1eb72e1

SHA-256:
2fbdc7a6e227206b903d7ba563fde4dc2ef6132349387ab0da4e6fac08ab395c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 10:12:23 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien.Iminent.Bundler (M)
16.2.15.9

File size:
50 KB (51,192 bytes)

Product version:
1.0.1343.0

Copyright:
Copyright (c) Microsoft Corporation. All rights reserved.

Original file name:
System.Windows.Interactivity.dll

File type:
Dynamic link library (Win32 DLL)

Bundler/Installer:
SIEN SuperInstall

Language:
Language Neutral

Common path:
C:\Program Files\iminent\system.windows.interactivity.dll

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/26/2010 1:31:06 PM

Valid to:
1/27/2012 1:31:03 PM

Subject:
CN=Iminent, O=Iminent, L=Paris, S=France, C=FR

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001266AC7D81A

File PE Metadata
Compilation timestamp:
2/17/2010 1:24:13 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:tyYelV2UVbduYyiX1alsuxKJWP0TLET6mCLYr:tjey2FamuxKJvTLEemCEr

Entry address:
0x9DEE

Entry point:
FF, 25, 00, 20, 20, 3B, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
32 KB (32,768 bytes)

Remove System.Windows.Interactivity.dll - Powered by Reason Core Security