uninstall.exe

Iminent Protection

SIEN S.A.

The application uninstall.exe by SIEN S.A has been detected as a potentially unwanted program by 9 anti-malware scanners.
Publisher:
Iminent  (signed by SIEN S.A.)

Product:
Iminent Protection

Version:
7.24.1.1

MD5:
a6586f494e76a793a2956eb76793c432

SHA-1:
8bd37837b650b1136cf62e43c173e67d3fb27699

SHA-256:
77d6a4e24cc92c95206ee93a431abfd0ee70fd03689e0b174bc9713ccc88ec6c

Scanner detections:
9 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 5:15:24 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/Iminent.AB
7.11.188.194

Dr.Web
Adware.Downware.8755
9.0.1.0337

herdProtect (fuzzy)
2014.11.9.5

Malwarebytes
PUP.Optional.Iminent
v2014.09.13.07

Qihoo 360 Security
Win32/Virus.Adware.1ef
1.0.0.1015

Reason Heuristics
PUP.SIENSA.J
14.9.13.7

Trend Micro House Call
Suspicious_GEN.F47V1125
7.2.337

Vba32 AntiVirus
BScope.Trojan-Dropper.Injector
3.12.26.3

VIPRE Antivirus
Iminent
33258

File size:
1.1 MB (1,198,752 bytes)

Product version:
7.24.1.1

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\iminent\inst\bootstrapper\uninstall.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
5/12/2014 9:20:39 AM

Valid to:
5/13/2015 9:20:39 AM

Subject:
E=support@sien.com, CN=SIEN S.A., O=SIEN S.A., L=Paris, C=FR

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121D12A06D1B366EFC0AF40F74B7D6BFEFE

File PE Metadata
Compilation timestamp:
9/11/2014 2:55:42 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:ZtueiHMFpZhYK0rkbWI4Mjnldnm49+yHpp5awGs7sk8WLEA4UDYBr:ae3bZe4bWWnld/Aav5awR7sW7bDYBr

Entry address:
0xB396D

Entry point:
E8, 4D, 42, 01, 00, E9, 89, FE, FF, FF, 6A, 0C, 68, 08, B4, 50, 00, E8, BD, 35, 00, 00, 33, DB, 89, 5D, E4, 33, C0, 8B, 7D, 08, 3B, FB, 0F, 95, C0, 3B, C3, 75, 14, E8, A8, 8D, FF, FF, C7, 00, 16, 00, 00, 00, E8, A5, 54, 00, 00, 33, C0, EB, 79, 33, C0, 8B, 75, 0C, 3B, F3, 0F, 95, C0, 3B, C3, 74, DE, 33, C0, 38, 1E, 0F, 95, C0, 3B, C3, 74, D3, E8, AD, 6F, 00, 00, 89, 45, 08, 3B, C3, 75, 0D, E8, 6F, 8D, FF, FF, C7, 00, 18, 00, 00, 00, EB, CA, 89, 5D, FC, 38, 1F, 75, 20, E8, 5B, 8D, FF, FF, C7, 00, 16, 00, 00...
 
[+]

Entropy:
6.4356

Code size:
919 KB (941,056 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ec2-54-243-144-249.compute-1.amazonaws.com  (54.243.144.249:80)

Remove uninstall.exe - Powered by Reason Core Security